Overview
- The intrusion was detected on July 26 and the extortion group ExfilSquad listed PNLD before publishing sample data and claiming about 135,000 records.
- PNLD confirmed that names, organisations and work email addresses for police, justice staff and some Ask the Police users were published but said there is no evidence passwords or security credentials were taken.
- PNLD has notified affected organisations, reported the incident to the Information Commissioner’s Office, and is working with the National Crime Agency and specialist cybersecurity firms.
- Independent researchers at VenariX say the leaks match a recurring pattern linked to misconfigured Microsoft Power Pages/Dataverse portals that allow anonymous reads, a hypothesis PNLD has not yet confirmed.
- Security officials warn the exposed contact information makes targeted phishing and safety threats more likely and could push public bodies to audit Power Pages settings after recent high‑profile breaches.