PNLD Data Breach: Information of UK Police Officers Leaked – Veri Sızıntısı

UK Police and Justice System Confirms Data Breach

The Police National Legal Database (PNLD), a legal database used by police forces in England and Wales, has suffered a cyberattack. The names and email addresses of police officers, staff, and justice system employees have been published on the dark web. The National Crime Agency has launched an investigation.

A British police helmet with a server room and data stream graphics in the background.

What Happened

The Police National Legal Database (PNLD), a critical legal reference system used by all 43 Home Office police forces in England and Wales, has confirmed it suffered a significant data breach. According to an official statement, cyber attackers published data obtained from the system on the dark web. The breach not only affected the police force but also "Ask the Police," a public Q&A service hosted on the same PNLD platform. Given the severity of the incident, the UK's top cybercrime unit, the National Crime Agency (NCA), has stepped in to lead a comprehensive investigation.

The PNLD is a central resource where police officers and judicial staff access up-to-date information on legal procedures, legislation, and best practices. Targeting this system constitutes a direct attack on the operational infrastructure of law enforcement. There are concerns that the breach could have a cascading effect on internal communications and personnel security. The investigation is multi-faceted, involving private cybersecurity firms alongside the NCA.

What Data Was Stolen

According to the data breach notification issued by PNLD, the leaked information belongs to a highly sensitive group. The compromised data includes the full names, associated organizations, and work email addresses of police officers, staff, criminal justice professionals, government partners, and other institutional customers. While this information alone may not have direct financial value, it is extremely valuable to cybercriminals. It serves as primary material for crafting sophisticated phishing attacks.

The organization emphasized that there is no evidence to suggest that passwords or other security credentials were compromised in the breach. However, even the combination of a name and a work email allows attackers to create highly convincing and targeted fake emails. The publication of this data on the dark web means it can now be bought and used by various criminal groups. The full scale of the leak has not been disclosed. Although PNLD's 2025-26 annual summary reported 108,429 police registrations, the exact number of individuals affected by the breach has not been officially announced.

How Did the Attack Happen

PNLD has not made an official attribution regarding the group behind the attack or its technical details. However, the timing of the event and analysis from the cybersecurity community offer some clues. An extortion group named ExfilSquad listed PNLD on its leak site on July 26, strengthening the possibility that this group may be responsible for the attack.

Cybersecurity firm VenariX reviewed data samples associated with 11 of ExfilSquad's 15 claimed victims. Their analysis revealed structures consistent with Microsoft Dataverse across all samples. This finding suggests that the attacks are likely part of a broader campaign targeting misconfigured Microsoft Power Pages portals. Power Pages is a platform that allows organizations to build public-facing websites. If table access permissions on these portals are set too permissively, anyone visiting the site can access sensitive data without even logging in.

This theory aligns with PNLD's technological infrastructure. The organization's 2023-24 annual summary stated that the database uses Microsoft Power Platform technology. Furthermore, PNLD's own data breach notification page references assets on Microsoft's content.powerapps.com domain, corroborating this connection. That said, neither PNLD nor VenariX has definitively confirmed that this specific vulnerability was exploited on a PNLD endpoint. While the investigation continues, it is believed the attack likely stemmed from a simple configuration error rather than a complex hacking operation.

Who Is Affected

This data breach puts two main groups at direct risk:

  • Police Officers and Criminal Justice Professionals: For these individuals, the greatest danger is targeted spear-phishing attacks. Attackers can use the stolen names, organizations, and email addresses to craft highly persuasive fake emails. For example, an email masquerading as a superior or another government agency could request sensitive information or trick the recipient into clicking a malicious attachment. A successful attack of this nature could lead to a deeper compromise of police networks and result in much larger security disasters.
  • Members of the Public Who Used "Ask the Police": This platform is a public service that allows citizens to ask the police questions on various topics. The leak of names and email addresses of people who used this service means their contact with the police has been exposed on criminal forums. Depending on the nature of their question, this could lead to serious risks beyond a privacy violation, such as blackmail, harassment, or social stigma.

What You Can Do

If you believe you may have been affected by this breach or wish to enhance your digital security in general, there are steps you can take. Staff working in the affected organizations must be more vigilant than ever. Carefully check the sender's address on incoming emails, do not click on links or open attachments in unexpected or suspicious-looking messages. If in doubt, verify the request through a different communication channel (e.g., a phone call). Using a Data Breach Search service to see what other incidents your personal data may have been involved in can give you an idea of your overall digital security posture. Members of the public should be wary of any suspicious emails or blackmail attempts that could be linked to this breach.

What the Company Is Saying

In its official announcement, PNLD attempted to address the situation with transparency. The notice stated that "Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web." It was underlined that there is no evidence of passwords or other security credentials being leaked.

Furthermore, they sought to allay public concern by clarifying that the system is not a crime recording system and does not hold confidential information relating to victims, witnesses, or offenders. PNLD announced that all affected organizations were promptly notified, provided with guidance, and the incident was reported to the UK's Information Commissioner's Office (ICO).

Source

https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.