U.K. Police Data Leaked on the Dark Web | PNLD Breach – Veri Sızıntısı

U.K. Police Data Leaked on the Dark Web

The Police National Legal Database (PNLD) breach exposed names and email addresses of police officers, government officials, and other judicial staff. The data has been published on the dark web.

A British police hat rests next to a computer keyboard, symbolizing the PNLD data breach news.

What Happened

The Police National Legal Database (PNLD), which provides legal information to police forces and judicial bodies in the United Kingdom, has confirmed it suffered a significant data breach. The incident, identified on July 26, resulted in data from the institution being published on the dark web. The leak includes sensitive contact information of police officers, government employees, and other individuals associated with the institution.

PNLD specifically emphasized that this database is not a crime-recording system and does not contain confidential information about victims, witnesses, or offenders. The organization operates as a support platform, offering legal information, products, and services to UK police forces and criminal justice organizations. This event has once again brought to light vulnerabilities in security infrastructure and the risks facing public sector employee data. Among the recent surge in Data Breach News, this attack targeting a public institution stands out due to its nature.

What Data Was Leaked

The data obtained by cybercriminals and published on the dark web focuses on corporate identity information rather than personal security details. The leaked information includes:

  • Full Names: The first and last names of the affected individuals.
  • Organization Information: The name of the institution or organization they work for.
  • Work Email Addresses: Corporate email addresses.

In its statement, PNLD mentioned there is no evidence to suggest that passwords or other security credentials have been compromised. However, the leak of even just names and work emails carries significant risks. As noted by the UK government, such data can be used to orchestrate highly convincing and personalized phishing attacks.

How Did the Attack Happen

PNLD has not yet publicly shared the technical details of how the attack was carried out. However, clues from the institution's technology infrastructure and analysis by cybersecurity firms offer important insights into the potential source of the attack.

PNLD's 2023-24 annual summary stated that the database uses Microsoft Power Platform technology. The presence of assets linked to Microsoft's content.powerapps.com domain on the breach notification webpage reinforced this connection. While this doesn't fully explain how the attacker obtained the data, it suggests the attack vector may be related to this platform.

An analysis by the cybersecurity firm VenariX sheds further light on the likely attack path. The firm examined data samples used in similar attacks that showed consistency with Microsoft Dataverse structures. According to VenariX's hypothesis, the attack likely stemmed from a configuration error involving the following steps:

  • A public Power Pages site granted broad access to Dataverse tables to the "Anonymous Users" role.
  • The site had an enabled Power Pages Web API or a legacy OData feed.

Microsoft's own documentation supports this theory. According to the documents, granting the "Anonymous Users" role access to a table makes its data visible to anyone visiting the site. The Web API interface also returns data based on these role permissions. This situation may have allowed sensitive data to be queried without authentication.

However, neither PNLD's official notice nor VenariX's report has definitively identified a PNLD-specific endpoint, permission setting, or API route. Therefore, the Power Pages link remains a strong hypothesis to be investigated, rather than a proven fact about the breach.

Who Is Affected

The breach affects numerous professionals from various levels of the UK's justice and security system. The groups whose data were exposed include:

  • Police officers and police staff
  • Criminal justice professionals
  • Employees of government partner organizations
  • PNLD customers
  • Some individuals who submitted questions through the "Ask the Police" feature

PNLD has not yet disclosed the total number of people affected by the breach. The institution's 2025-26 annual summary mentions 108,429 police registrations and support for all 43 Home Office police forces. However, this figure represents the platform's total user base and does not reflect the number of breach victims.

What Can You Do

If you believe you have been affected by this breach or work in a similar institution, you need to be particularly cautious of phishing attacks. Attackers can use the stolen names, titles, and organization information to craft highly credible emails. These emails may appear to come from a colleague or a superior and may ask you for passwords, personal information, or files.

  • Be Skeptical of Emails: Do not click on links or download attachments in unexpected or suspicious-looking emails, even if they appear to be from someone you know.
  • Verify Information: Always confirm any sensitive request received via email (e.g., password reset, money transfer) through a different communication channel, such as a phone call.
  • Check the Sender's Address: Ensure the email address is correct. Attackers often use fake addresses with minor alterations, such as a changed letter.

What Does the Company Say

PNLD announced that it has taken a series of steps following the incident. The institution has contacted all affected organizations to provide them with information and guidance. Users affected through the "Ask the Police" service have also been reached directly via email.

As part of the legal process, the incident has been reported to the Information Commissioner's Office (ICO), the UK's data protection authority. Additionally, it was stated that the investigation is being conducted in collaboration with the National Crime Agency (NCA) and specialist cybersecurity organizations. As of August 3, 2026, PNLD has not yet publicly shared critical information such as when the intrusion began, how long it lasted, or how much data was taken.

Source

https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.