Over 100,000 UK Police officers, staff and criminal justice professionals had their personal data stolen in a cyberattack on the Police National Legal Database (PNLD). The threat group ExfilSquad claimed responsibility for the breach, publishing a 1.9 GB cache of stolen records on the dark web and demanding a ransom.

What You Need to Know

The PNLD is a database used by police and legal professionals to access criminal justice information. The breach exposed names, organizations and work email addresses of 114,000 PNLD subscribers and 21,000 Ask the Police users. Passwords and security credentials were not compromised, but the exposed contact details could enable targeted phishing attacks. The National Crime Agency and the Information Commissioner's Office (ICO) have been notified and are investigating.

Breach Details and Data Exposed

PNLD confirmed the attack in a press release, stating that the breach occurred over a weekend. The organization did not disclose how attackers gained access but said it has hired cyber-security specialists. The stolen data was published on the dark web, and ExfilSquad claimed to have obtained 135,000 contact records, sharing samples to support their claim.

  • Names and organizations: Exposed for each affected individual, enabling identification.
  • Work email addresses: Leaked for both PNLD subscribers and Ask the Police users.
  • No passwords: PNLD stated there is no evidence passwords or security credentials were taken.

ExfilSquad is a relatively new threat actor not previously known for major attacks. Prior to this incident, the group claimed responsibility for breaching Analog Devices, a US semiconductor company. The group’s dark web post included a ransom demand, though PNLD has not confirmed whether a payment was made.

Why This Matters

The breach represents a significant security failure for a system relied upon by the UK’s criminal justice system. Police officers, staff and legal professionals now face heightened risk of phishing and social engineering attacks, as their work email addresses and organizational affiliations are now publicly available. The exposure of contact details for Ask the Police users, a public-facing legal advice website, also raises privacy concerns for ordinary citizens who sought assistance. This incident underscores the vulnerability of government databases and the growing sophistication of cybercriminal groups targeting law enforcement infrastructure. Moving forward, agencies must prioritize stronger access controls, regular security audits and rapid incident response to protect sensitive personnel data.

Response and Investigation

PNLD immediately notified The National Crime Agency, which launched an investigation into the breach. The organization also contacted the ICO, as required under UK data protection law. All affected organizations were contacted in the days following the incident and provided with guidance. PNLD’s statement emphasized that it is working with cyber-security experts to contain the damage and prevent future incidents. The National Crime Agency has not yet released details on the investigation or any potential leads on ExfilSquad’s location or methods.