mimile
Back to feed

PNLD breach exposes UK police and government contact details on dark web

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

PNLD breach exposes UK police and government contact details on dark web

The Police National Legal Database (PNLD) confirms that contact details of UK police, government and criminal justice professionals were exposed on the dark web following a breach identified on July 26. The data, including names and work email addresses, raises phishing concerns, according to UK government guidance. PNLD says no passwords or security credentials were compromised, even as it has not disclosed victim numbers or intrusion duration.

The Data Exposure

PNLD confirmed that names, organisations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers were published on the dark web. Some names and email addresses from Ask the Police queries were also exposed, which UK government guidance warns could make phishing messages more convincing. PNLD described the exposed fields in its breach notice but did not provide a victim total. The database reported 108,429 police registrations and support for all 43 Home Office police forces in its 2025-26 annual summary, though that figure reflects user base, not breach victims.

PNLD Investigation

PNLD stated it contacted all affected organisations and provided guidance. Affected Ask the Police users received an email with information. The organisation notified the Information Commissioner’s Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organisations. As of August 3, PNLD had not disclosed how many people were affected, when the intrusion began, how long access lasted, or how much information was taken. It maintained that no passwords or security credentials were compromised.

Technical Assessment

PNLD’s 2023-24 annual summary states the database uses Microsoft Power Platform technology, and a breach-notice page referenced assets on Microsoft’s content.powerapps.com domain, The Hacker News confirmed. Security firm VenariX reviewed samples from 11 of ExfilSquad’s 15 claimed victims and found Dataverse-consistent structures. In one case, a public portal returned records without authentication, matching published data. VenariX assessed the likely path as a public Power Pages site with broad Anonymous Users access to Dataverse tables, possibly via an enabled Power Pages Web API. Microsoft documentation warns that granting Anonymous Users access makes table data visible to anyone.

What's Next

The ICO and NCA investigations are ongoing, and PNLD may face regulatory scrutiny if it is found to have failed to secure the data adequately. It remains unclear whether the exposed email addresses will lead to widespread phishing campaigns against UK law enforcement.