
THE UK Police National Legal Database has been breached, exposing personal details of officers and justice staff on the dark web. A post by ChaosLensX first drew attention to the leak, claiming the extortion group ExfilSquad is behind the theft. The compromised material includes names, organisational affiliations and work email addresses for thousands of users. Although passwords are not reported as part of the dump, the exposure of contact information raises the prospect of targeted social engineering.
The database is managed by West Yorkshire Police and supports the public Ask the Police service, which runs on a Microsoft Power Pages portal. According to Infosecurity Magazine, the leak is estimated at around 1.9 gigabytes of data. Investigators have pointed to a possible misconfiguration in that portal as the entry point that allowed the attackers to extract the information. The National Crime Agency is assisting the investigation alongside the force’s own cyber security team.
Security Affairs notes that the breach has increased the risk of phishing campaigns aimed at police personnel and justice staff. The leaked dataset does not appear to contain credential material, but attackers can use the harvested names and email addresses to craft convincing lures. Recipients are urged to treat unexpected messages with caution and to verify the sender before clicking links or opening attachments. Enabling multi‑factor authentication on linked accounts is also recommended as a precautionary measure.
The Hacker News reports that ExfilSquad has claimed responsibility for the intrusion and says it retains the full 1.9 GB dump. The group’s statement appeared on a dark web forum shortly after the data was posted for sale. Law enforcement agencies have confirmed they are monitoring the forums for any further distribution of the material. No ransom demand has been made public, suggesting the motivation may be purely exploitative or aimed at future extortion.
The PNLD serves approximately 108,429 police registrations, meaning a substantial portion of the UK law‑enforcement community could be affected. Organisations are advised to review any external‑facing portals for configuration errors, especially those built on low‑code platforms like Power Pages. Regular credential audits and the principle of least privilege should be applied to reduce the attack surface. Staff training programmes should emphasise the signs of spear‑phishing and the importance of reporting suspicious communications promptly.
Although no evidence of password theft has surfaced, the incident highlights the need for continuous monitoring of law‑facing systems and for staff to remain vigilant against social engineering. Organisations should consider deploying anomaly detection tools that flag unusual data exports or access patterns from public‑facing applications. Collaboration with national cyber crime units, as seen here with the NCA, can accelerate containment and attribution efforts. Ultimately, maintaining a hardened configuration and a well‑informed workforce remains the best defence against similar breaches.