
More than 100,000 UK police officers and staff have had their names and work contact details published on the dark web after hackers breached the Police National Legal Database (PNLD), exposing information belonging to people who work in law enforcement and the wider criminal justice system.
Detected in July, PNLD later confirmed that information including names, organisations, and work email addresses had been compromised and published online. However, the agency further said there is currently no evidence that passwords or other security credentials were accessed.
This incident matters because the leaked information belongs to people whose jobs can make them easy targets. It also shows how a database that does not hold highly sensitive crime records can still contain information that attackers may find valuable.
What Was Exposed
Police sources told The Times that details belonging to 114,000 PNLD subscribers were leaked, with the vast majority believed to be police officers. The database is used by police forces across England and Wales to access legal information while carrying out their work.
The breach went beyond police personnel, as information from 2,615 Crown Prosecution Service staff, 617 Home Office employees, 588 National Crime Agency staff and 402 Ministry of Defence personnel were also reportedly exposed.
Another 21,000 email addresses belonging to members of the public who had previously submitted questions through the Ask the Police website were published.
PNLD has stressed that it is not a crime-recording system and does not hold confidential information about victims, witnesses or offenders. The organisation has also confirmed that the affected information was limited to contact and organisational details.
Exfilsquad Claims Responsibility
A relatively new cybercriminal group called ExfilSquad has claimed responsibility for the attack. The group said it stole about 1.9GB of data containing roughly 135,000 records, including information from PNLD subscribers and Ask the Police users. Samples of the stolen information were subsequently posted online.
The group has also been linked to other recent attacks involving UK government organisations, with the Department for Education, for example, suffering a separate breach in which more than 600,000 pieces of data were reportedly stolen.
The exact method used to gain access to PNLD has not been publicly disclosed, but the agency says it is working with specialist cybersecurity organisations and the National Crime Agency, while the Information Commissioner’s Office has also been notified.
Why The Leaked Details Matter
Names and work email addresses may appear less serious than passwords or confidential case records, but cybersecurity experts have warned that such information can make targeted phishing and social engineering easier.
A leaked list can give attackers a clearer picture of who works for a particular organisation and provide information they can use when attempting to make fraudulent messages appear legitimate.
The PNLD breach is, therefore, a reminder that protecting public-sector data is not only about securing classified information. Basic identity and contact records can also become a security problem when thousands of them are exposed at once.
For now, the investigation continues, and there is no evidence that passwords or other security credentials were compromised.
