Cyber & Technology — 2026-08-04

UK Police National Legal Database Breach Exposes 114,000 Officers Details on Dark Web Alongside MoD and NCA Data

BLUFExfilSquad will likely dump the full 135,000-record dataset within 30 days of July 26, arming threat actors with named contacts across NCA, MoD, and CPS for targeted social engineering campaigns.

A cyberattack on the UK's Police National Legal Database, detected on July 26 and claimed by extortion group ExfilSquad, exposed contact information for an estimated 114,000 PNLD subscribers, the vast majority police officers, along with 21,000 email addresses of members of the public who used the affiliated Ask the Police site 12. PNLD confirmed the breach and said full names, organizations, and work email addresses of police officers, staff, criminal justice professionals, and government partners were compromised, and that no passwords or security credentials appear affected 13. Police sources told The Times that the leaked data also included contact information for 2,615 CPS staff, 617 Home Office employees, 588 NCA personnel, and 402 Ministry of Defence workers 4. ExfilSquad, which claims to have stolen roughly 135,000 records totaling 1.9 GB, is the same group The Times has linked to a prior breach at the Department for Education that exposed over 600,000 records 24. PNLD said the National Crime Agency and Information Commissioner's Office have been notified and are assisting the investigation 2.

Analysis
ExfilSquad will likely publish or offer the full 135,000-record dataset on a dark web forum within 30 days of the July 26 breach discovery, mirroring the extortion pattern it set with the Department for Education leak. This is a moderate-confidence judgment resting on the group's track record of following through once samples surface, against the chance PNLD or law enforcement disrupts distribution first. The Register's primary confirmation anchors converging secondary accounts on subscriber and department breakdowns, though ExfilSquad's claimed haul may overstate the true scope as leverage; PNLD's confirmed categories reflect the actual verified exposure. A full dump would arm threat actors with named contacts across the NCA, MoD, Home Office and CPS for targeted phishing and doxxing beyond the officer roster already exposed, forcing security teams from breach containment toward individualized threat mitigation for thousands of named personnel rather than continued monitoring.
4 sources
  1. Police National Legal Database confirms data theft after dark web leak - The Register
  2. ExfilSquad hackers leak info of over 100,000 UK police officers, staff - BleepingComputer
  3. PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web - The Hacker News
  4. Police at serious risk as more than 100,000 officers and staff have details leaked on dark web - GB News

View in full brief →

UNCLASSIFIED // OPEN SOURCE