Police National Legal Database confirms data theft after dark web leak

Aug 03, 2026 - 19:17
0 0
Police National Legal Database confirms data theft after dark web leak

cyber-crime

ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education

The Police National Legal Database (PNLD) is the latest UK public sector outfit to admit that cybercriminals made off with its data, including the names and work email addresses of police officers, justice staff, government partners, and customers.

The legal lookup service relied upon by police forces and criminal justice agencies across the UK said it discovered the "data security incident" on July 26 and is investigating alongside specialist cybersecurity firms and the National Crime Agency. 

According to the PNLD, the leaked information includes the names, organizations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and customers. It insists there is "no evidence" that passwords or other authentication data were compromised.

The breach also affected Ask the Police, a public-facing legal advice website operated by PNLD. There, the fallout appears limited to the names and email addresses of people who previously submitted questions through the service.

That's about where the explanation ends. PNLD has yet to say how attackers got in, when the data was stolen, how many people were affected, or whether anyone tried to shake it down before the information appeared online. West Yorkshire Police, which operates PNLD, did not immediately respond to The Register’s questions. 

However, the breach appears linked to the same extortion crew that last week claimed responsibility for a similar breach of the Department for Education (DfE). The group, which calls itself "ExfilSquad," currently lists both the PNLD and DfE among its latest victims on its dark web leak site, seen by The Register

For PNLD, the crooks claim to have lifted a 1.9 GB dataset containing roughly 135,000 law enforcement contact records, including names, email addresses, and police force areas. The DfE listing boasts of around 600,000 parent and staff contact records, plus another 7,000 from its Turing Portal. The education department confirmed last week that more than 607,000 records had indeed been exposed.

The DfE has confirmed that the compromised information was limited to customer service contact details from its Customer Help Portal and Turing Scheme, and said no other departmental data had been accessed.

Like most cyber-extortion outfits, ExfilSquad doesn't exactly do understatement. Its leak site warns victims that once data appears there, it is "NEVER leaving the public eye," before suggesting any ransom would amount to little more than a rounding error compared with the legal bills that might follow.

The DfE and PNLD's confirmations don't validate everything ExfilSquad posts on its leak site. It also lists Microsoft as a victim, alleging a 13 GB haul containing millions of records, password hashes, internal support tickets, and access permissions. 

Having two organizations confirm breaches claimed on its leak site makes ExfilSquad harder to ignore. Whether the gang's other boasts are equally well founded, or simply the usual cybercrook embellishment, remains to be seen. ®

Updated to add at 1517 UTC, August 3:

The North East Regional Organised Crime Unit told The Reg it is investigating the breach. It told us "No ransom demand has been received."
It also confirmed some numbers, stating the data of around 114,000 PNLD subscriber was involved.

It added: "This involves the names, work email addresses and work organisation of police officers and other criminal justice partners. There are also around 21,000 email addresses of members of the public who have previously used ‘Ask the Police’. There is no evidence to suggest that passwords or other security credentials have been compromised."

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User