A cyberattack on the U.K.'s Police National Legal Database has exposed the contact information of more than 100,000 police officers, staff, and criminal justice professionals, in one of the most significant breaches of law enforcement data in recent British history.
The intrusion, first reported by BleepingComputer, was detected on Sunday, July 26, and subsequently claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records totaling 1.9 GB of data.
PNLD, which has operated as an online legal resource for more than 30 years, serves all 43 Home Office police forces in England and Wales as well as the British Transport Police.
In a statement, PNLD confirmed that the breach exposed the full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. The names and email addresses of users who submitted questions through the service's public-facing "Ask the Police" website were also considered compromised.
ExfilSquad's own accounting of the stolen data breaks down to approximately 114,000 PNLD subscribers and 21,000 Ask the Police users. The group published sample data to support its claims and has demanded a ransom in exchange for not releasing the remaining stolen records.
PNLD said no passwords or other security credentials were found to have been compromised. The organization also stated it does not hold confidential information relating to victims, witnesses, or offenders, and that no such data was impacted.
"All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner's Office (ICO) has also been notified," PNLD said in its statement.
The incident is being investigated with assistance from cybersecurity experts and the National Crime Agency. PNLD confirmed the breach and the publication of contact details but has not publicly attributed the intrusion or disclosed how attackers gained access.
ExfilSquad is the same threat actor that recently claimed an attack on American semiconductor company Analog Devices, underscoring a pattern of targeting organizations whose data carries significant operational or reputational sensitivity.
The exposure of law enforcement contact records carries risks that extend well beyond typical corporate data breaches. Officers' names, email addresses, and organizational affiliations could be leveraged for targeted phishing campaigns, social engineering, or, in more serious scenarios, attempts to identify or intimidate personnel.
The notification of the ICO signals that PNLD is operating under the U.K.'s data protection obligations, which can carry significant financial penalties depending on the findings of any regulatory inquiry.
With the National Crime Agency now involved and the attacker still actively making ransom demands, investigators face pressure to assess the full scope of the exfiltration before any additional data is published.
Disclaimer