The United Kingdom’s Police National Legal Database (PNLD) has confirmed a significant cybersecurity breach in which cybercriminals stole data belonging to police officers, police staff, criminal justice professionals, government partners and customers. According to the organisation, the compromised information includes names, affiliated organisations and official work email addresses. However, PNLD said there is currently no evidence that passwords or other authentication credentials were compromised in the incident.
PNLD stated that it detected the security breach on July 26 and immediately launched an investigation with the assistance of specialist cybersecurity firms and the National Crime Agency (NCA). The organisation also confirmed that the incident affected its public legal advice platform, Ask the Police, where the names and email addresses of people who had previously submitted legal queries were also exposed. Based on the information available so far, there is no indication that more sensitive personal data from the platform was compromised.
The organisation has not yet disclosed how the attackers gained access to its systems, when the data was stolen, how many individuals were initially affected, or whether any ransom demand was made before the stolen information appeared online. West Yorkshire Police, which operates PNLD, has also declined to provide further technical details while the investigation remains ongoing.
Responsibility for the breach has been claimed by the cyber-extortion group ExfilSquad, the same threat actor that recently claimed responsibility for a separate breach involving the UK’s Department for Education (DfE). According to the group’s dark web leak site, the attackers stole approximately 1.9 GB of data from PNLD containing around 135,000 law enforcement contact records, including names, official email addresses and police force details.
Subsequently, the North East Regional Organised Crime Unit (NEROCU) confirmed that the incident affected the data of approximately 114,000 PNLD subscribers. In addition, the email addresses of around 21,000 members of the public who had previously used the Ask the Police service were also exposed. Authorities reiterated that there is no evidence that passwords or other security credentials were compromised. Investigators further confirmed that no ransom demand has been received in connection with the incident.
The same cybercriminal group has also claimed responsibility for the recent breach of the Department for Education, alleging that it obtained approximately 607,000 customer contact records along with an additional 7,000 records from the department’s Turing Portal. The department has already confirmed that customer contact details associated with its Customer Help Portal and Turing Scheme were exposed but stated that no other departmental systems or sensitive operational data were accessed.
ExfilSquad has listed several other prominent organisations on its dark web leak portal, including Microsoft, claiming to possess large volumes of internal data. However, those claims have not been independently verified. Cybersecurity analysts note that while the confirmation of breaches by two UK public sector organisations lends credibility to some of the group’s claims, allegations involving other organisations remain unverified and continue to be investigated.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said attacks targeting government institutions often extend far beyond the theft of contact information. Stolen official identities and email addresses can later be exploited in highly targeted phishing campaigns, business email compromise attacks and sophisticated social engineering operations against government agencies and law enforcement personnel. He advised affected organisations to conduct comprehensive digital forensic investigations, review access controls, enforce multi-factor authentication, strengthen continuous network monitoring and carry out regular security audits. He also urged employees and members of the public to remain cautious of suspicious emails, fake login pages and unsolicited identity verification requests, as attackers frequently use stolen official contact information to launch follow-up cyberattacks.
