All incidents

UK Police National Legal Database leak exposes officers' contact details

breachopenAug 3, 2026 — Aug 3, 2026
UK Police National Legal Database leak exposes officers' contact details

THE Police National Legal Database (PNLD) in the United Kingdom has confirmed a data breach that exposed the names and email addresses of officers and justice staff, with the leaked information appearing on the dark web and raising the risk of targeted phishing attempts.

The breach was traced to a misconfigured Microsoft Power Pages portal supporting the public Ask the Police question and answer service, which inadvertently released personal details without requiring authentication.

Although no passwords or financial data were disclosed, the exposed contact details could be used in social engineering campaigns, and the National Crime Agency is leading the investigation into the incident.

No specific threat actors have been identified so far, but the presence of the data on underground forums suggests it may be leveraged by criminal groups seeking to impersonate officials or gain internal access.

The incident underscores the ongoing challenges organisations face when deploying low‑code platforms, highlighting the need for rigorous configuration reviews and continuous monitoring of public‑facing services.

Officers should treat any unexpected correspondence with caution, enable multi‑factor authentication on all work accounts, and report suspicious messages to their internal security teams, while administrators must audit Power Pages implementations for excessive permissions and enforce least‑privilege access.

Intelligence briefing updated Aug 3, 2026

Timeline Coverage

Swipe to explore timeline