ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A devastating cyberattack on the UK’s Police National Legal Database (PNLD) has compromised the contact details of over 100,000 police officers and other criminal justice professionals. The intrusion was carried out by the ExfilSquad data extortion group, which claims to have stolen a staggering 135,000 records from the database.

The PNLD is an online legal resource service used by 43 Home Office police forces in England and Wales, as well as the British Transport Police. It’s been a vital tool for law enforcement agencies for over three decades, providing access to thousands of contact details and other information. However, on July 26, ExfilSquad claimed responsibility for the attack, which exposed the full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners.

The breach also compromised the names and email addresses of users who submitted questions through PNLD’s public-facing website, Ask the Police. This online platform provides answers to common policing and legal questions, making it a valuable resource for both the public and law enforcement agencies. According to PNLD, no passwords or other security credentials were compromised in the attack.

The investigation into the breach is ongoing, with assistance from cybersecurity experts and the National Crime Agency (NCA). PNLD has confirmed that all affected organizations have been contacted and provided with further information and guidance. The Information Commissioner’s Office (ICO) has also been notified of the incident.

ExfilSquad claims to have stolen 1.9 GB of data from PNLD, including approximately 135,000 records. The group demands a ransom in exchange for not releasing the remaining stolen data. This is not the first time ExfilSquad has claimed responsibility for an attack; they recently targeted American semiconductor company Analog Devices.

The breach raises serious concerns about the security of sensitive information and the potential consequences of such attacks. As we’ve seen with previous breaches, attackers often use stolen data to extort money or gain unauthorized access to systems. It’s essential that organizations take proactive measures to protect themselves against such threats.

For individuals and organizations affected by this breach, it’s crucial to remain vigilant and monitor their accounts for any suspicious activity. PNLD has assured users that no confidential information related to victims, witnesses, or offenders was compromised in the attack.

As we continue to navigate the ever-evolving landscape of cyber threats, it’s essential to remember that security is a continuous process. Organizations must test every layer of their defenses before attackers do. This can be achieved through regular breach and attack simulation tests, which help identify vulnerabilities and improve incident response plans.


Source: Bleeping Computer — 2026-08-03