top of page

UK Police Officers’ Contact Details Leaked on Dark Web After PNLD Database Breach

In late July 2026, a newly emerged cybercrime group known as ExfilSquad claimed responsibility for breaching the Police National Legal Database (PNLD), a key online resource used by UK police forces for criminal law guidance and legal assistance. The attackers published the personal and professional contact details of more than 100,000 police officers, staff, and other criminal justice professionals on the dark web.



What Happened


The incident was identified on Sunday, 26 July 2026. ExfilSquad, a relatively new group that rapidly listed multiple victims across several countries, posted samples of the stolen data and later made larger portions available via torrent links. The PNLD dataset was described as approximately 1.9 GB uncompressed and contained around 135,000 records.


According to the official notification on the PNLD website, the compromised information includes the names, organisations (or police forces), and work email addresses of police officers, police staff, and other criminal justice professionals and government partners. The data has been published on the dark web. PNLD stated there is currently no evidence that passwords or other security credentials were compromised.


The database, which supports the 43 Home Office police forces in England and Wales as well as wider law enforcement and criminal justice partners, is hosted by West Yorkshire Police. Importantly, officials have stressed that the PNLD does not hold confidential victim, witness, or offender information, and the leaked material is limited to contact and organisational details.



Broader Context


The PNLD breach occurred alongside a larger attack claimed by the same group against the Department for Education (DfE). That incident exposed more than 600,000 records from the department’s help-desk portal, including names, email addresses, phone numbers, and job titles of parents, school staff, university personnel, and government officials. Combined, the two breaches affected over 740,000 pieces of data.



ExfilSquad demanded payment from the affected organisations, warning that failure to pay would result in the full release of the data. Samples were initially posted freely to prove the legitimacy of their claims.


Official Response


PNLD is continuing to investigate the incident and has referred itself to the Information Commissioner’s Office (ICO). The DfE has also reported its breach to the ICO and is working with the National Cyber Security Centre and the National Crime Agency. Both organisations emphasised that the exposed data is limited to customer-service style contact details and that swift containment measures were taken.



Sources familiar with the PNLD investigation have described the risk level as relatively low compared with a compromise of more sensitive systems such as the Police National Computer or Police National Database. However, concerns remain about potential secondary risks, including targeted phishing, social engineering, or credential stuffing if individuals reused passwords across systems.Implications


While the breach does not appear to expose highly sensitive operational or personal data, the release of thousands of police and criminal justice email addresses and force affiliations still creates practical risks. Officers and staff may face increased phishing attempts, impersonation, or unwanted contact. It also serves as a reminder of the ongoing pressure on public-sector digital infrastructure in the UK


.As of early August 2026, investigations continue. Affected individuals have been advised to remain vigilant about unexpected communications and to use official channels when verifying any contact related to police or justice matters.


This incident highlights the persistent challenges facing even specialised government and law-enforcement databases in an era of increasingly opportunistic and rapidly operating cybercrime group


Comments


bottom of page