PNLD breach leaks UK police contact data to dark web

The UK Police National Legal Database (PNLD) has confirmed a data breach that exposed contact details for police officers, criminal justice professionals, government partners and customers, with samples now circulating on dark web leak sites.[1][2][5] The incident, identified on 26 July, involves names, organisations and work email addresses linked to users of the service.[1][2][4] PNLD said there is currently no evidence that passwords or other security credentials have been compromised.[1]

Threat intelligence reporting and media coverage indicate the leak contains roughly 100,000 to 135,000 law enforcement contact records, although PNLD has not publicly confirmed exact figures.[2][4][8] The newly surfaced ransomware and extortion group ExfilSquad has claimed responsibility for the attack, listing PNLD on its leak site and advertising a dataset of 135,000 law enforcement contact records.[2][4][9] Listings associated with ExfilSquad state that internal files were exfiltrated in a ransomware incident and that data attributed to PNLD is now available for download.[4][5]

PNLD is a legal information service that provides criminal law resources and guidance to UK police forces and criminal justice organisations, rather than an operational crime database.[1][3] The organisation stressed that the system is distinct from the Police National Computer and Police National Database and does not hold confidential information on victims, witnesses or offenders.[1] Initial statements describe the compromised data as limited to customer service contact details, including names, forces or organisations and work email addresses.[1][2]

Security analysts warn that exposing named officer and staff email addresses, force affiliations and related contact data raises the risk of highly targeted phishing, impersonation and harassment campaigns against law enforcement personnel.[5][7][8] One breach-tracking site characterises the incident as critical, noting that large-scale exfiltration of UK law enforcement contact records creates immediate safety risks for officers and undermines operational security.[5] The PNLD attack appears linked to a broader campaign in which ExfilSquad also targeted the UK Department for Education, stealing hundreds of thousands of records and demanding payment to prevent further leaks.[2][8]

As of early August, PNLD had not publicly disclosed when the intrusion began, how long attackers maintained access, or how many individuals were affected.[1] No technical details of the attack vector, exploited vulnerabilities or initial access pathway have been released, leaving open questions about whether weaknesses lay in PNLD’s infrastructure, a supplier environment or user authentication.[1][2] Until fuller forensic findings emerge, defenders across UK policing and government are focusing on immediate containment measures such as reviewing portal access, monitoring for suspicious login activity, and updating security awareness messaging for staff whose details may now be circulating in criminal forums. Experts recommend that organisations linked to PNLD treat the incident as a high-risk contact data exposure, tightening email security controls, enforcing multi-factor authentication and preparing tailored guidance for personnel who could be targeted in follow-on social engineering attacks.

References

  1. PNLD Breach Exposes U.K. Police and Government Contact Details on …
  2. Hackers steal sensitive data from UK Department for …
  3. Police National Legal Database Data Breach in 2026
  4. Police National Legal Database Listed by ExfilSquad …
  5. Police National Legal Database data breach — ExfilSquad ransomware leak (2026)
  6. 🚨 PNLD breach puts U.K. police and government contact details on the …
  7. Data of 100,000 UK police officers leaked on dark web
  8. ExfilSquad Breaches Police National Legal Database

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply