top of page
perceptive_background_267k.jpg

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

Published:

3 augustus 2026 om 15:04:39

Alert date:

3 augustus 2026 om 16:00:47

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Data Breach & Exfiltration, Critical Infrastructure

A cyberattack targeting the UK's Police National Legal Database (PNLD) has resulted in the compromise and leak of contact data belonging to over 100,000 police officers and criminal justice professionals. The threat actor group known as ExfilSquad claimed responsibility for the breach. The leaked data includes personal and contact information of UK law enforcement personnel. This incident represents a significant breach of sensitive law enforcement data with potential risks to officer safety and operational security. The scale of the breach affecting over 100,000 individuals makes it a high-impact incident for UK policing and the criminal justice system.

Technical details

The Police National Legal Database (PNLD), a UK online legal resource service used by 43 Home Office police forces in England and Wales and British Transport Police, suffered a cyberattack detected on Sunday, July 26. The ExfilSquad data extortion group claimed responsibility, alleging theft of 1.9 GB of data comprising approximately 135,000 contact records: 114,000 PNLD subscribers and 21,000 'Ask the Police' platform users. Exposed data includes full names, organizations, and email addresses of police officers, staff, criminal justice professionals, government partners, and Ask the Police users. No passwords or security credentials were confirmed compromised. No confidential victim, witness, or offender data was held or impacted. ExfilSquad published sample data and demanded a ransom to prevent full release. The National Crime Agency (NCA) and cybersecurity experts are assisting in the investigation. The Information Commissioner's Office (ICO) has been notified.

Mitigation steps:

1. Affected organizations have been contacted by PNLD with further information and guidance following the breach. 2. Monitor for phishing or social engineering attempts targeting exposed officers and staff using leaked email addresses and names. 3. Enforce password resets and review access credentials for PNLD accounts as a precautionary measure, even though no password compromise was confirmed. 4. Report suspicious contact or extortion attempts to the National Crime Agency (NCA). 5. Notify the Information Commissioner's Office (ICO) per data breach obligations — PNLD has already done so. 6. Conduct a thorough investigation with cybersecurity experts to determine the attack vector and prevent recurrence. 7. Review and harden access controls, authentication mechanisms, and monitoring on systems holding law enforcement personnel data. 8. Do not pay the ransom demand, and coordinate with law enforcement regarding extortion communications from ExfilSquad.

Affected products:

Police National Legal Database (PNLD)
Ask the Police (public-facing PNLD website)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page