UK police database breach exposes data of 100K+ officers and staff – Expert Perspectives

The Police National Legal Database (PNLD), a legal reference service used by all 43 Home Office police forces in England and Wales, confirmed a cyberattack that exposed the contact information of more than 100,000 police officers, police staff and criminal justice professionals.
The breach was discovered on July 26, and the ExfilSquad extortion group has claimed responsibility, alleging it stole 135,000 contact records.
According to PNLD, the compromised information includes names, employing organizations and work email addresses of police officers, government partners and criminal justice personnel, along with the names and email addresses of members of the public who used the "Ask the Police" service.

Seemant Sehgal, Founder & CEO, BreachLock:

"A database of 135,000 verified identities across law enforcement and criminal justice, with employing organizations attached, is not contact information in the ordinary sense. That combination tells an adversary exactly who works where, in what capacity, and how to reach them directly. The downstream risk to be concerned about here is social engineering, targeted harassment, and covert approaches to personnel who would otherwise be a lot more difficult to identify and map."

Denis Calderone, CTO, Suzu Labs:

“A simple misconfiguration in a Microsoft Power Pages portal was the impetus for this breach. PNLD’s Anonymous Users web role had read access to backend Dataverse tables, which means the subscriber database was queryable through a standard API call by anyone who visited the site without logging in. And similar to the open S3 bucket issue that was so prevalent a few years ago, ExfilSquad didn’t need to deploy malware or exploit a zero-day, they just had to hunt for misconfigured endpoints. And what was sitting behind those endpoints happened to be the names, force assignments, and work emails of 135,000 police officers, CPS prosecutors, and criminal justice professionals across all 43 forces in England and Wales.

“The real danger here isn’t that officers may get phished. Police are trained observers, professionally skeptical, and most UK forces have had security awareness reinforcement since the PSNI incident in 2023. The danger is what this data enables criminals to do to everyone else. A verified name, force assignment, and work email for a real officer is everything you need to impersonate police when contacting witnesses, victims, solicitors, or other agencies. For organized crime groups specifically, this directory is a counter-intelligence tool. You can cross-reference names and force assignments against your own operations to map who might be investigating you. And then there’s the 21,000 members of the public from Ask the Police, people who already have a relationship with law enforcement and are primed to trust communications that appear to come from police email addresses.

“This is the same group and the same access method that hit the Department for Education the week before, exposing 607,000 records. Researchers have found Dataverse-consistent structures across 11 of ExfilSquad’s 15 claimed victims, so this is clearly a systemic configuration problem across UK public sector Power Pages deployments. If your organization runs Power Pages, open an incognito browser window and query your /_api/ and /_odata endpoints right now. See what comes back without credentials. Microsoft provides a tenant-level governance control that blocks unauthenticated Dataverse reads while still allowing public form submissions. That control should have been validated before deployment, not discovered after 135,000 law enforcement contacts land on the dark web.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

"Threat actors often use basic contact information as the starting point for phishing campaigns, social engineering attacks, and credential theft. Law enforcement personnel face unique risks because of the nature of their work and data they may have access to. Even if the exposed information is only of contact details, these can be combined with publicly available information or previously breached datasets to build detailed profiles of officers, investigators, or even government personnel. In 2023 I discovered 500k records that were exposed that contained records associated with vehicle seizures conducted by Ireland’s national police, I have seen firsthand how law enforcement data can become publicly accessible and the risks that come with it. Once data is exposed, you can’t put the genie back in the bottle.

Law enforcement data exposures by cybercriminals is highly concerning and more steps must be taken to protect the identities and contact information of officers, investigators, and support personnel. Even when these incidents expose limited information, multiple breaches over time can provide threat actors or even nation states with enough intelligence to identify organizational structures, identify specialized units, and target individuals based on their roles or launch a more sophisticated cyberattack. The most concerning part to me is that in the age of AI where criminals have access to advanced technology, we do not know how data exposed today will be used tomorrow."

Articles similaires

Special Reports

4 August 2026

UK police database breach exposes data of 100K+ officers and staff – Expert Perspectives

The Police National Legal Database (PNLD), a legal reference service used by all 43 Home Office (…)

Special Reports

13 July 2026

“U.S. and allies warn Russian hackers are targeting critical infrastructure routers” – Experts Perspectives

Cybersecurity agencies from the U.S. and allied countries warned that hackers linked to Russia’s (…)

Special Reports

6 July 2026

Pegasus spyware investigation raises new concerns

Insights from Noelle Murata ( COO, Xcape, Inc. ) about the latest reporting on Pegasus spyware (…)