The Police National Legal Database (PNLD), the legal reference service operated by West Yorkshire Police and used by all 43 Home Office forces in England and Wales, has confirmed that contact details for police officers, police staff, criminal justice professionals, government partners and customers were stolen and published on the dark web. PNLD says it identified the "data security incident" on Sunday 26 July 2026 and disclosed it publicly on 3 August. The data extortion group ExfilSquad claimed responsibility and says it holds 1.9 GB of data covering roughly 135,000 records. PNLD itself has not published a victim count, so figures vary: headline reporting from BleepingComputer and Infosecurity Magazine cites "more than 100,000" officers and staff, while the 135,000 figure comes from ExfilSquad's own leak site listing and analysis of published samples rather than from any official tally. Igor's Lab makes this distinction explicitly, noting PNLD "has not yet published a specific number of affected individuals or records."
What Happened
PNLD is an online legal resource that has been in service for more than 30 years, supplying case law, legislation and procedural guidance to the 43 Home Office police forces in England and Wales and to British Transport Police. Infosecurity Magazine reports its user base also extends to the Crown Prosecution Service, the Independent Office for Police Conduct and His Majesty's Courts and Tribunals Service. Escudo Digital additionally lists Ministry of Defence and Home Office personnel among those affected, though that breakdown appears in only one lower tier source and is not reflected in PNLD's own statement.
According to PNLD's 3 August notice, reproduced across the security press, the service has been "working with specialist cybersecurity organizations and the National Crime Agency to investigate the circumstances and take appropriate action." The Information Commissioner's Office was notified, and PNLD says affected organisations were contacted in the days following discovery of the incident.
The disclosure is notably thin on operational detail. As The Register put it, PNLD "has yet to say how attackers got in, when the data was stolen, how many people were affected, or whether anyone tried to shake it down before the information appeared online." West Yorkshire Police did not respond to The Register's questions at time of publication. There is no confirmed dwell time, no confirmed initial access vector, and no confirmed count of affected individuals.
One point of terminology matters for accurate triage: PNLD is not a criminal records system. Igor's Lab stresses that PNLD must not be confused with the Police National Computer or the Police National Database, and PNLD itself states it holds no confidential information relating to victims, witnesses or offenders.
What Was Taken
PNLD's own description of the compromised data set is consistent across every outlet that carried the statement: names, organisations and work email addresses of police officers, police staff, other criminal justice professionals, government partners and customers.
A second population was hit through Ask the Police, the public facing legal question service PNLD operates. Names and email addresses of members of the public who had previously submitted a question through that portal were also published. PNLD says anyone affected in that group has already received an email with guidance.
On volume, the accounts diverge and should be reported as a range:
- PNLD: no figure published.
- ExfilSquad's leak site claim, cited by The Register, Infosecurity Magazine and BleepingComputer: approximately 135,000 records in a 1.9 GB dataset, including names, email addresses and police force areas.
- Press headline framing: "more than 100,000" police officers and staff.
- Escudo Digital: approximately 135,000 contact records, and reports the archive is available via a torrent link. That torrent distribution detail is single sourced from a lower tier outlet and should be treated as unverified.
Both BleepingComputer and Escudo Digital report that ExfilSquad demanded a ransom in exchange for not releasing the remainder of the stolen data; the amount has not been disclosed. Sample data was published to substantiate the claim.
Critically, PNLD states there is "no evidence to suggest that passwords or other security credentials have been compromised." That claim is repeated verbatim across all outlets and is currently the organisation's position, not an independently verified finding.
Why It Matters
The absence of credentials or case data does not make this a low impact breach. A validated pairing of full name, employing force or agency, role context and official work email address is close to an ideal seed corpus for targeted social engineering against UK policing and criminal justice bodies. Igor's Lab spells out the abuse path directly: attackers can pose as colleagues, IT service providers, other authorities or internal support desks, and the data lends those messages credibility that generic phishing lacks. ThinScale reaches the same conclusion, warning that the exposure "significantly increases the risk of highly targeted phishing and impersonation attacks against public sector organisations."
The Ask the Police population carries a distinct risk profile. Attackers know not only who those individuals are but that they had a prior relationship with a policing portal, which allows pretexting that references a plausible, real prior interaction.
There is also a pattern here. The Register notes ExfilSquad currently lists both PNLD and the Department for Education among its recent victims on its dark web leak site. The DfE listing claims roughly 600,000 parent and staff contact records plus a further 7,000 from its Turing Portal, and the education department confirmed a figure above 607,000. Two UK public sector data holders in successive weeks, both contact data at scale, both extortion led, suggests a deliberate campaign against government adjacent platforms rather than opportunistic single hits.
The regulatory backdrop is unforgiving. On 5 August, two days after PNLD's disclosure, the ICO issued the Metropolitan Police Service with an enforcement notice and reprimand over two separate and unrelated incidents involving erroneous disclosure of personal data, citing failures under section 40 of the Data Protection Act 2018 and "multiple weaknesses" in training compliance, monitoring and governance. That action concerns different facts and a different force, and should not be read as an ICO finding about PNLD. It does, however, establish the regulator's current appetite for formal action against policing bodies, and the ICO has been notified of the PNLD incident.
The Attack Technique
No root cause has been confirmed. PNLD has not disclosed the initial access vector, the dwell time, or whether the theft was a single extraction event.
Two lower tier sources point toward a common hypothesis. Rescana frames the incident in its headline as exposure "via Microsoft Power Platform Misconfiguration." ThinScale is more cautious, noting that "researchers have suggested similarities between this breach and a wider campaign involving misconfigured Microsoft Power Pages environments," while adding that "no technical root cause has been confirmed for PNLD."
This should be treated as an unconfirmed hypothesis, not a finding. It appears only in OTHER tier sources, is absent from PNLD's statement and from all three established security outlets covering the incident, and ThinScale itself hedges it. Defenders may reasonably treat misconfigured low code portal environments as a plausible avenue worth auditing on general principle, but attributing this specific breach to that cause is not currently supported.
What is well established is the actor's operating model: exfiltration and extortion without an encryption stage, victim listings on a dark web leak site, publication of sample data to prove possession, a ransom demand against withholding the remainder, and eventual publication when unpaid.
What Organizations Should Do
- Assume the contact data is public and permanent. If your organisation has personnel in the 43 Home Office forces, British Transport Police, CPS, IOPC, HMCTS or partner agencies, brief staff that their name, employer and work email are now in criminal hands and will be used as phishing raw material.
- Raise the bar on out of band verification for anything involving credentials, MFA enrolment, payment changes or case data. Impersonation of internal IT and support functions is the most likely near term abuse, and the attacker knows real names and real addresses.
- Tune detection for internal impersonation specifically. Alert on external senders spoofing display names of known personnel, on lookalike domains for force and agency names, and on inbound mail referencing PNLD or Ask the Police as a pretext.
- Audit low code and externally facing portal environments, including Microsoft Power Pages and Power Platform deployments, for anonymous access, over permissive table permissions and exposed OData endpoints. The link to this specific incident is unconfirmed, but the broader campaign it may belong to is not hypothetical.
- Inventory third party legal, reference and lookup services in your supply chain. PNLD is exactly the kind of low profile shared platform that sits outside routine vendor risk reviews while holding directory scale data on your workforce.
- Confirm your regulatory clock is running correctly. PNLD notified the ICO and contacted affected organisations within days. If you receive such a notification, your own downstream assessment and, where applicable, notification duties begin at that point.
- Extend awareness messaging to members of the public who interacted with Ask the Police. Their exposure is smaller in field count but higher in personal targeting value, since the attacker knows the specific service they used.
Sources: Data breach: 100K+ British police officers' contact details leaked... | Metropolitan Police Service issued with enforcement notice and repr... | ExfilSquad hackers leak info of over 100,000 UK police officers, staff | Police National Legal Database confirms data theft after ... | UK's Police National Legal Database Reveals Data Breach | PNLD Data Breach: Police Contacts Published on the Dark Web | PNLD Breach Exposes UK Police and Government Contact Details on the... | PNLD Data Breach Exposes UK Police and Government Contact Informati...