Police National Legal Database
Incident posture
Linked entities
- Victim
- Police National Legal Database
- Threat actors
- 1 actor
- Sources
- 3 sources
Timeline
Summary
Police National Legal Database confirmed a data theft incident discovered on July 26, 2026, after a dark web leak exposed names, work email addresses of police officers, justice staff, government partners, and customers; ExfilSquad claimed responsibility.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The Police National Legal Database (PNLD), a centralized legal lookup service used by police forces and criminal justice agencies across the United Kingdom, suffered a data security incident that was identified on July 26, 2026. The PNLD is managed by the West Yorkshire Police and serves all 43 police forces in England and Wales, as well as the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct, and His Majesty's Courts and Tribunals Service. The incident was publicly disclosed in a statement issued on August 3, 2026, in which the PNLD confirmed that information including the names, organizations, and work email addresses of police officers, staff, other criminal justice professionals, government partners, and customers had been compromised and subsequently published on the dark web. The PNLD stated that there was no evidence to suggest that passwords or other security credentials had been compromised. The Ask the Police service, which is operated by the PNLD as a public-facing legal advice website, was also affected, with the names and email addresses of individuals who had previously submitted questions to the service being published on the dark web as a result of the incident. The PNLD noted that affected users of the Ask the Police service were contacted directly via email with additional information and guidance.
The data extortion group ExfilSquad claimed responsibility for the breach, asserting that it had obtained a 1.9 GB dataset containing approximately 135,000 law enforcement contact records. The group stated that it had exfiltrated data from multiple UK public sector organizations, including the UK Department for Education, from which it claimed to have stolen 600,000 parent and staff contact records. ExfilSquad first emerged on July 26, 2026, and subsequently published data dumps for 13 of its claimed 15 victims on August 7, 2026, via torrents, alleging that those organizations had not met its ransom demands. The full archive released by the group was labeled in the format "[victim]_exfilsquad" and reportedly contained a combined total of 382.64 GB of data and approximately 27 million records across the 13 affected organizations. In the case of the PNLD specifically, the breach affected around 114,000 subscribers, with the stolen data comprising names, work email addresses, and organizational affiliations of police officers and criminal justice partners, alongside approximately 21,000 public email addresses from the Ask the Police service. The North East Regional Organised Crime Unit confirmed that it was investigating the incident and noted that no ransom demand had been received by the PNLD.
The methodology behind the broader ExfilSquad campaign, as analyzed by Fortra Intelligence and Research Experts (FIRE), pointed to misconfigured Microsoft Power Pages portals as the leading theory for the initial attack vector that enabled data exfiltration. Power Pages is a Software-as-a-Service platform designed for creating external-facing business websites, and the researchers identified a known configuration issue in which the Anonymous Users web role, when assigned to a table permission, allows table data to be read by anyone visiting the site. The leaked data formations were consistent with Microsoft Dataverse exports, suggesting that unauthorized read access to Microsoft D365 CRM and ERP instances was likely achieved through these exposed portals, which can be accessed via an API at the path "/_api/". Fortra noted that automated scanning for exposed Power Pages sites is a known technique, and the firm stated that it was able to identify over 10,000 potential publicly accessible Power Pages instances during its research. Because the breaches reached just 15 victims rather than tens of thousands, the researchers concluded that a broader D365 vulnerability was unlikely to be the source of the data breach, with victims instead being identified through crawling for misconfigured portals or other enumeration techniques. The PNLD incident is among the confirmed data breaches tied to this activity, alongside the UK Department for Education, the City of Atlanta, the District of Columbia Public Schools, Zenith Bank Plc, and Analog Devices, among others, although Zenith Bank and Analog Devices were not present in the August 7 data dump despite being included in the original 15-victim list.
In response to the incident, the PNLD stated that it had been working with specialist cybersecurity organizations and the National Crime Agency to investigate the circumstances and take appropriate action since the incident was identified. The PNLD also clarified that it does not hold any confidential information relating to victims, witnesses, or offenders, framing the scope of the compromise as limited to contact and organizational information. ExfilSquad's leak site included a notice warning that once a company's data was posted, it would never leave the public eye and would be passed around the internet indefinitely, framing the requested payment as a minimal cost compared to potential litigation expenses. The group also listed Microsoft as a victim, alleging a 13 GB haul of records, password hashes, and internal support tickets, though this claim was not elaborated in the source material. The UK government's stated intention to introduce a de facto ban on public sector organizations paying extortion demands to cyber adversaries contextualized the unlikelihood of any ransom payment from the PNLD. Dray Agha, senior manager of the security operations center EMEA at Huntress, noted that while the absence of compromised passwords provided some relief, exposing the names and work emails of UK police and justice staff on the dark web provided cybercriminals with a ready-made directory for launching targeted spear-phishing and social engineering attacks against personnel within the justice system.
Sources
Sources available to members: 3 sources.