Overview
- The Police National Legal Database (PNLD) confirmed a data security incident after contact information for police officers, staff and criminal‑justice users was published on the dark web and affected organisations were notified.
- Investigators and PNLD say the intrusion was detected on July 26 and the Information Commissioner’s Office and National Crime Agency have been notified as specialist cyber teams probe the incident.
- A data‑extortion group calling itself ExfilSquad has claimed responsibility, posted sample records and says it published about 1.9GB of data and roughly 135,000 records, while PNLD has not independently confirmed the exact haul.
- PNLD and investigators report there is no evidence that passwords or other security credentials were taken, but security firms have flagged that exposed names and work emails create a high risk of targeted phishing and social‑engineering attacks.
- Security researchers have identified a pattern consistent with misconfigured Microsoft Power Pages/Dataverse portals allowing anonymous access as a plausible access route, though PNLD has not confirmed a root cause and regulatory action by the ICO remains possible.