Seemant Sehgal, Founder & CEO, BreachLock:
"A database of 135,000 verified identities across law enforcement and criminal justice, with employing organizations attached, is not contact information in the ordinary sense. That combination tells an adversary exactly who works where, in what capacity, and how to reach them directly. The downstream risk to be concerned about here is social engineering, targeted harassment, and covert approaches to personnel who would otherwise be a lot more difficult to identify and map."
Denis Calderone, CTO, Suzu Labs:
“A simple misconfiguration in a Microsoft Power Pages portal was the impetus for this breach. PNLD’s Anonymous Users web role had read access to backend Dataverse tables, which means the subscriber database was queryable through a standard API call by anyone who visited the site without logging in. And similar to the open S3 bucket issue that was so prevalent a few years ago, ExfilSquad didn’t need to deploy malware or exploit a zero-day, they just had to hunt for misconfigured endpoints. And what was sitting behind those endpoints happened to be the names, force assignments, and work emails of 135,000 police officers, CPS prosecutors, and criminal justice professionals across all 43 forces in England and Wales.
“The real danger here isn’t that officers may get phished. Police are trained observers, professionally skeptical, and most UK forces have had security awareness reinforcement since the PSNI incident in 2023. The danger is what this data enables criminals to do to everyone else. A verified name, force assignment, and work email for a real officer is everything you need to impersonate police when contacting witnesses, victims, solicitors, or other agencies. For organized crime groups specifically, this directory is a counter-intelligence tool. You can cross-reference names and force assignments against your own operations to map who might be investigating you. And then there’s the 21,000 members of the public from Ask the Police, people who already have a relationship with law enforcement and are primed to trust communications that appear to come from police email addresses.
“This is the same group and the same access method that hit the Department for Education the week before, exposing 607,000 records. Researchers have found Dataverse-consistent structures across 11 of ExfilSquad’s 15 claimed victims, so this is clearly a systemic configuration problem across UK public sector Power Pages deployments. If your organization runs Power Pages, open an incognito browser window and query your /_api/ and /_odata endpoints right now. See what comes back without credentials. Microsoft provides a tenant-level governance control that blocks unauthenticated Dataverse reads while still allowing public form submissions. That control should have been validated before deployment, not discovered after 135,000 law enforcement contacts land on the dark web.”
Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:
"Threat actors often use basic contact information as the starting point for phishing campaigns, social engineering attacks, and credential theft. Law enforcement personnel face unique risks because of the nature of their work and data they may have access to. Even if the exposed information is only of contact details, these can be combined with publicly available information or previously breached datasets to build detailed profiles of officers, investigators, or even government personnel. In 2023 I discovered 500k records that were exposed that contained records associated with vehicle seizures conducted by Ireland’s national police, I have seen firsthand how law enforcement data can become publicly accessible and the risks that come with it. Once data is exposed, you can’t put the genie back in the bottle.
Law enforcement data exposures by cybercriminals is highly concerning and more steps must be taken to protect the identities and contact information of officers, investigators, and support personnel. Even when these incidents expose limited information, multiple breaches over time can provide threat actors or even nation states with enough intelligence to identify organizational structures, identify specialized units, and target individuals based on their roles or launch a more sophisticated cyberattack. The most concerning part to me is that in the age of AI where criminals have access to advanced technology, we do not know how data exposed today will be used tomorrow."





