The Police National Legal Database (PNLD) has confirmed a security breach that resulted in the exposure of contact information for police officers, government officials, and related professionals on the dark web. This data, which includes names, organizations, and work email addresses, was published by a group known as ExfilSquad. The breach, discovered on July 26, 2026, did not compromise passwords or other security credentials. However, the exposure of this information could lead to more convincing phishing attempts targeting the affected individuals, as noted by UK government guidance.
PNLD provides legal information and services to UK police forces and criminal justice organizations. It has assured that the breach does not involve the Police National Computer or the Police National Database and does not contain confidential information about victims or offenders. The organization has reached out to all affected parties, offering further information and guidance on the situation. The Information Commissioner's Office has been notified, and PNLD is working with the National Crime Agency and cybersecurity specialists to address the issue.
While the exact number of affected individuals and the details of the intrusion remain undisclosed, PNLD reported support for all 43 Home Office police forces and 108,429 police registrations in its 2025-26 annual summary. Microsoft Power Platform technology underpins the database, and assets hosted on Microsoft's domain were referenced in the breach notice. VenariX, a cybersecurity firm, analyzed samples from the breach and found structures consistent with Microsoft's Dataverse, suggesting a potential misuse of Power Pages configurations. However, this remains a hypothesis rather than a confirmed cause.
Microsoft documentation indicates that granting anonymous access to Dataverse tables can expose data publicly, a configuration that VenariX suggests reviewing. Despite listing PNLD on its leak site, ExfilSquad has not been officially linked to the breach by PNLD, and there is no evidence of ransomware or malware use in the examined campaign material.


