Overview
The Police National Legal Database (PNLD) has confirmed that police officer, government employee, and public contact information was stolen and published on the dark web. The breach — claimed by a newly emerged extortion group calling itself ExfilSquad — exposed approximately 114,000 law enforcement subscriber records and over 20,000 public user email addresses from the "Ask the Police" service.
The incident is part of a wave of UK public-sector data breaches in late July 2026, with at least three government departments compromised within days of each other.
What Is the PNLD?
The Police National Legal Database is an online legal resource used by all 43 Home Office police forces in England and Wales. It provides legal guidance to officers and criminal justice personnel for daily operations. It also operates the "Ask the Police" public inquiry service — a platform through which members of the public can submit questions to law enforcement.
The database holds contact records for a significant portion of the entire UK police service, making it an extremely sensitive target.
What Was Exposed?
PNLD confirmed the following data categories were compromised:
| Data Category | Count |
|---|---|
| Police officer and criminal justice staff records (names, forces, work emails) | ~114,000 |
| ExfilSquad's claimed total | 135,000 |
| "Ask the Police" public user email addresses | 20,000+ |
| Government bodies represented | NCA, MOD, Home Office, CPS |
At least one unnamed source told The Times that passwords were also among the stolen data, though PNLD has not officially confirmed this. The National Crime Agency confirmed that "limited personal details relating to a number of NCA officers" were included.
The Threat Actor: ExfilSquad
ExfilSquad is a new data-extortion group that appeared publicly on July 26, 2026, when it simultaneously posted stolen data from 14–15 alleged victims across five countries on its Tor-based data leak site.
Key Characteristics
- Exfiltration-only model — no confirmed ransomware encryption, just data theft and extortion
- Operates a Tor-based dark web leak site with payment deadlines
- Listed government bodies, corporations, and made a disputed claim against Microsoft
- Motivated by financial extortion rather than ideology
- 11 of 15 claimed victims show data structures consistent with Microsoft Dataverse — suggesting a platform-level vulnerability rather than individual organization compromises
Suspected Attack Vector: Microsoft Power Pages
The leading hypothesis — assessed by security firm VenariX — is a misconfigured Microsoft Power Pages environment:
- PNLD uses Microsoft Power Platform technology (evidenced by assets on
content.powerapps.com) - Power Pages sites with overly permissive "Anonymous Users" access granted to Dataverse tables expose their data to any visitor without authentication
- The enabled Power Pages Web API or legacy OData feed would allow bulk data extraction
- Microsoft's own documentation explicitly warns that granting the Anonymous Users role access to a Dataverse table makes its data publicly visible
This hypothesis has not been officially confirmed by PNLD or Microsoft. No specific misconfigured endpoint has been publicly identified.
UK Government Dataverse Pattern
VenariX found that 11 of ExfilSquad's 15 claimed victims show Dataverse-consistent data structures — suggesting the group actively targeted UK public-sector entities using Microsoft Power Platform infrastructure, rather than discovering these organizations through opportunistic scanning.
Timeline
| Date | Event |
|---|---|
| Unknown | Initial intrusion — PNLD has not disclosed when access began |
| July 26, 2026 | ExfilSquad publishes 135,000 records + UK DfE 607K dump simultaneously |
| July 26, 2026 | PNLD confirms breach; notifies ICO, NCA, NCSC |
| August 2026 | Investigation ongoing; full scope not yet determined |
UK Response
- PNLD notified the Information Commissioner's Office (ICO), is cooperating with the National Crime Agency and National Cyber Security Centre
- Police Federation chairwoman Tiff Lynch called it a "serious concern for officer and staff safety" and demanded stronger cybersecurity investment
- Security expert Jake Moore (ESET) noted government organisations "are being seen as softer targets because they have not invested enough to properly protect private information"
- Officers whose data was exposed — particularly those who worked in serious organised crime units — expressed fears about personal safety
The Broader UK Public Sector Wave
The PNLD breach did not occur in isolation:
- The UK Department for Education was hit around the same time, with ExfilSquad publishing over 607,000 records
- Three UK government departments were compromised within days
- ExfilSquad appears to have specifically targeted UK public-sector entities using Microsoft Power Platform, suggesting targeted reconnaissance rather than opportunistic discovery
What Affected Officers Should Do
- Assume your work email and name are public — treat any associated accounts as potentially targeted for spear phishing
- Review personal operational security — be alert to social engineering attempts using work details as context
- Change passwords on any account tied to your work email address
- Report suspicious contact to your force's cyber crime or professional standards unit
- Monitor for follow-on phishing — data from this breach is likely to fuel credential phishing campaigns targeting police and government staff
Sources
- The Hacker News — PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- Breachsense — Police National Legal Database Data Breach
- SOCRadar — Dark Web Profile: ExfilSquad
- Cybernews — 600K UK Education Department records leaked