A previously unknown extortion crew calling itself ExfilSquad has published stolen data from the UK's Police National Legal Database (PNLD) and the Department for Education (DfE) on a dark web leak site, exposing the names, employing forces and work email addresses of police officers and criminal justice staff. Record counts differ by source: ExfilSquad's own leak-site posting claims 135,000 PNLD records (IBTimes UK, BreachNews, The Record), while press coverage of the published data describes "more than 100,000" officers and staff affected (Anadolu Agency, GB News). On the DfE side, the department itself puts the figure at roughly 607,000 records and stresses these are lines of data rather than distinct individuals. The Guardian counts more than 740,000 stolen data entries across both victims combined. The National Cyber Security Centre has confirmed it is "supporting law enforcement colleagues in response to an incident affecting the Police National Legal Database."
What Happened
ExfilSquad listed both UK organisations on its dark web leak site in late July 2026. BreachNews dates the initial PNLD forum claim to 25 July 2026; IBTimes UK reports samples of both the PNLD and DfE datasets were posted on 26 July 2026. The Guardian and The Record covered the DfE extortion attempt from 29 July, and the wider dumping of police data was reported late on Sunday 2 August, according to Anadolu Agency.
PNLD is an online criminal law resource governed by West Yorkshire Police, supplying legislation, case summaries, national standard offence wording and legal guidance to all 43 Home Office police forces in England and Wales. Its user base also includes British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct and His Majesty's Courts and Tribunals Service, which is what makes a contact-record dump from a single platform unusually broad in reach.
The DfE incident hit two separate portals, which the department has named as the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, the latter used to administer the programme for UK students studying abroad.
There is no claim from any source that systems were encrypted. This is pure data-theft extortion: ExfilSquad is demanding payment from both the DfE and PNLD to prevent full publication, according to screenshots reviewed by reporters. Anadolu Agency quotes the group's leak-site boilerplate: "Once your company's data is posted here, it's NEVER leaving the public eye... The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking."
Accounts of scope differ beyond the two confirmed victims. IBTimes UK reports ExfilSquad listed 14 alleged victims across five countries on the same day, including a claim involving Microsoft, and notes that most of those remain independently unverified. Anadolu Agency, citing The Times, reports the campaign also compromised data from the Ministry of Defence, the Home Office, the National Crime Agency and the Crown Prosecution Service. Those wider claims are attributed and should not be treated as confirmed. The Home Office declined to comment on the PNLD breach.
What Was Taken
For PNLD, the confirmed data categories are consistent across sources: names of police officers and criminal justice personnel, the force or organisation employing them, and work email addresses. PNLD has also confirmed that some names and addresses of members of the public who used its "Ask the Police" service were caught in the dump. GB News reports more than 20,000 members of the public had email addresses leaked. PNLD has been explicit that the database holds no protected investigation material and no information on victims, witnesses or offenders.
Two source-specific claims go further and are worth flagging separately. The Guardian reports that the PNLD theft includes passwords used to access the site. BreachNews describes the published sample as containing portal account details, login timestamps, authentication settings and internal system identifiers alongside the contact data. Neither detail appears in PNLD's own statement, so treat both as reported rather than confirmed. If either holds, the incident escalates from a contact-list leak to a credential and session-metadata exposure.
For the DfE, the stolen material is customer service contact data: full names, job titles, email addresses and phone numbers belonging to government officials, senior school leaders, university staff, parents and other members of the public. The DfE says no bank details or comparably sensitive information were involved and that the risk to individuals is not considered high. Volume figures for DfE range from "more than 600,000" lines (The Record, The Guardian) to 607,000 records (IBTimes UK, Anadolu Agency), with Anadolu Agency separately using a "more than 500,000" figure in the same report. The department's own 607,000 total-records number is the best-supported.
Why It Matters
Contact-detail breaches are routinely dismissed as low severity. That framing breaks down when the contacts are serving police officers. A dataset mapping named individuals to specific forces gives organised crime groups, hostile states and harassment campaigns a ready-made targeting index against people whose operational security depends on separating their professional identity from their personal exposure. One affected staff member quoted by Anadolu Agency described having previously been forced into safe houses and to sell vehicles because of their work, saying the leak "puts officers at serious risk."
The verified work email addresses are also a high-grade phishing asset. Anyone holding force-attributed addresses for criminal justice staff can craft credible lures impersonating PNLD itself, force IT, or CPS correspondence. Combine that with the DfE dump and the actor holds a cross-sector UK public-sector contact graph.
There is a structural lesson here too. PNLD is a shared legal reference platform, not a case management system, and it likely sat well down most forces' risk registers. But its user directory aggregates identity data from 43 forces plus the CPS, IOPC and HMCTS. Low-sensitivity systems with high-sensitivity user bases are a systematically underweighted class of asset.
Finally, the extortion economics. UK government policy is not to pay ransoms, and The Record notes the government has moved forward with plans to bar public sector and critical national infrastructure bodies from making ransomware payments, though this is not yet law. ExfilSquad's pitch, framing payment as cheaper than litigation, is aimed squarely at organisations with GDPR exposure. Against a non-paying government target it is likely to fail, which raises the probability of full publication rather than negotiation.
The Attack Technique
Initial access remains unknown. BreachNews states plainly that the actor provided no information on when the intrusion occurred, how access was obtained, or whether access persists. No source in this set identifies an exploited CVE, a compromised vendor, or a phishing vector, and neither PNLD nor the DfE has published technical detail.
What the available evidence does suggest is a pattern rather than a mechanism. Both victims were breached through web-facing self-service portals: the PNLD user platform, the DfE Help Desk Self-Service Portal and the Turing Scheme Portal. The absence of encryption across all claimed victims, combined with a same-day bulk listing of 14 alleged targets across five countries, is consistent with an opportunistic mass-harvesting operation, likely automated scanning against a common portal platform, framework or authentication weakness, rather than bespoke targeting of UK policing. Anadolu Agency reports the DfE hack is believed to have been financially rather than ideologically motivated. Treat the mass-harvesting read as an inference from the pattern, not as an established finding.
If the BreachNews description of the sample is accurate, the exported records include portal account internals and authentication settings, which would point to database-level access rather than scraping of a user-facing directory.
What Organizations Should Do
- Inventory shared and third-party portals by user base, not by data classification. Any platform holding an account directory for law enforcement, judiciary, defence or safeguarding staff should be risk-rated on who its users are, not just on what content it stores. PNLD is the template case.
- Force credential rotation and session invalidation on any portal implicated in a leak. Given The Guardian's report of stolen passwords and BreachNews's account of authentication settings and login timestamps in the sample, PNLD-linked credentials should be treated as compromised until proven otherwise, with particular attention to password reuse against force SSO and email.
- Push targeted phishing warnings to affected staff now, ahead of full publication. The exposed data supports highly credible impersonation of PNLD, force IT and CPS. Warn specifically about password reset lures and "verify your account" messaging referencing the breach itself, a standard follow-on after leak-site publication.
- Enforce phishing-resistant MFA on all externally reachable public sector portals. Contact-plus-credential dumps are only monetisable at scale where a password alone still grants access. Legacy shared-service platforms are frequently the last holdouts.
- Run egress and query-volume monitoring on user directory tables. Bulk extraction of an entire account directory should be detectable as an anomaly regardless of how the actor authenticated. Neither victim appears to have detected the theft before the actor published.
- Prepare for publication, not negotiation. With UK policy against payment and proposed legislation to prohibit it outright for public sector bodies, plan on the assumption the full dataset goes public. That means notification workflows, ICO reporting, and individual risk assessments for officers whose personal safety depends on non-attribution, including those in protected or undercover roles.
- Monitor for follow-on aggregation. Cross-referencing leaked force-attributed identities against prior breach corpora and open social profiles is the realistic next-stage harm. Threat intel teams should be watching for combined datasets, not just the original dump.
Sources: PNLD Breach Exposes U.K. Police and Government ... | Cyber extortionists steal data from UK Department for Education Th... | Hackers steal sensitive data from UK Department for ... | Personal data of 100,000 UK police officers leaked on dark web | Exfilsquad Dumps 135,000 UK Police Records on Dark Web Alongside Ed... | Police data leak: More than 100,000 officers and staff have details... | UK Police Legal Database Allegedly Breached | Cybercriminals breach UK Department for Education and law enforceme...