Personal data linked to more than 100,000 UK police and justice users was leaked after a breach of the Police National Legal Database.
The personal information of more than 100,000 police officers, police staff, other criminal justice professionals, government partners, and customers has been compromised and published on the dark web following a cyberattack on the Police National Legal Database (PNLD).
PNLD confirmed the breach after the stolen data surfaced online. According to the organization, the exposed information includes names, work email addresses, and the organizations individuals are associated with. It also said there is no evidence that passwords or other security credentials were compromised.
The cybercrime group ExfilSquad has claimed responsibility for the attack, alleging it stole around 1.9GB of data, including approximately 114,000 PNLD subscriber records and 21,000 records linked to the public-facing Ask the Police service. Samples of the data have reportedly been released online, but PNLD has not confirmed the volume of information claimed by the group.
Some early reports described the breach as affecting “100,000 police officers,” but PNLD said the compromised database covered a much broader group of users. Those affected include police officers, police staff, other criminal justice professionals, government partners, customers, and users of its public services, rather than sworn officers alone.
PNLD is an online legal database used by police forces and criminal justice organizations across England and Wales. It provides legislation, case law, legal guidance, and offence information to support investigations and day-to-day policing. The organization stressed that the affected system does not contain confidential records relating to victims, witnesses, suspects, or offenders.
After identifying the breach, PNLD said it engaged specialist cybersecurity experts to investigate and reported the incident to the National Crime Agency (NCA) and the Information Commissioner’s Office (ICO). The investigation remains ongoing.
Although no passwords or login credentials are believed to have been exposed, cybersecurity experts warn that the leaked information could still be exploited. Names, work email addresses, and organizational details can be used in targeted phishing campaigns or social engineering attacks aimed at police personnel and others working across the criminal justice sector.
The incident has also brought attention to ExfilSquad, a cybercrime group that has recently claimed responsibility for several attacks against organizations in the UK and elsewhere. At this stage, authorities have not disclosed how the attackers gained access to PNLD’s systems, and the investigation into the breach is continuing.
Source: PNLD Police National Legal Database and The Register
Related articles :
__Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__