Executive Summary
On July 26, 2026, the Police National Legal Database (PNLD) identified a data security incident resulting in the exposure of contact information for police officers, criminal justice professionals, government partners, and customers. The compromised data, which included names, organisations, and work email addresses, was subsequently published on the dark web. Some members of the public who had submitted questions to the Ask the Police service were also affected. There is no evidence to suggest that confidential information about victims, witnesses, or offenders was compromised. While PNLD and several sources state that passwords were not affected, one media report cites a source claiming password theft; this remains unconfirmed. The threat actor ExfilSquad claimed responsibility, posting data samples and demanding payment. The incident is under investigation by PNLD, the National Crime Agency, and the Information Commissioner’s Office, with support from cybersecurity specialists. The technical root cause has not been officially disclosed, but analysis suggests a likely misconfiguration of a public-facing application. The breach highlights the risk of targeted phishing and social engineering attacks using the exposed contact details. All affected organisations and individuals have been notified, and the investigation is ongoing as of August 3, 2026.
Technical Information
The PNLD breach represents a significant compromise of contact information for law enforcement and government personnel in the United Kingdom. The incident was first identified on July 26, 2026, and confirmed by official PNLD disclosure and multiple independent media sources. The exposed data set includes names, organisations, and work email addresses of police officers, staff, criminal justice professionals, government partners, and customers. Additionally, some members of the public who interacted with the Ask the Police service were affected.
Technical analysis by third-party security researchers, including VenariX, suggests that the likely attack vector was exploitation of a misconfigured public-facing application, specifically a Microsoft Power Platform/Power Pages portal. This misconfiguration may have allowed anonymous users to access backend Dataverse tables containing sensitive contact information. The presence of "Dataverse-consistent structures" in the leaked data supports this hypothesis, although PNLD has not officially confirmed the root cause. The attack did not involve ransomware, malware, or lateral movement within the network, as confirmed by both PNLD and independent technical reviews.
The threat actor ExfilSquad claimed responsibility for the breach, posting data samples on a leak site and demanding payment. This group is not previously known in public threat intelligence, and attribution is based solely on their public statements and the matching of leaked data to the compromised information. The tactics used align with data extortion operations, focusing on exfiltration and ransom demands rather than destructive activity.
The breach did not affect confidential information about victims, witnesses, or offenders, as the PNLD does not store such data. The primary risk is the potential for targeted phishing and social engineering attacks leveraging the exposed contact details. The incident also affected the Department for Education (DfE) in a related but separate breach, with a combined total of over 740,000 records reportedly exposed, including 135,000 records attributed to the PNLD breach.
All affected organisations and individuals were notified promptly, and the Information Commissioner’s Office (ICO) was informed. The National Crime Agency (NCA) and National Cyber Security Centre (NCSC) are involved in the ongoing investigation. As of August 3, 2026, the full scope of the breach, including the exact number of affected individuals and the technical root cause, has not been publicly disclosed.
Affected Versions & Timeline
The breach affected the Police National Legal Database (PNLD) and the Ask the Police service, both hosted by West Yorkshire Police and accessible to all 43 Home Office police forces in England and Wales. The incident was identified on July 26, 2026, with public disclosure and media reporting following in the subsequent days. The Department for Education (DfE) was also impacted in a related attack.
The timeline is as follows: On July 26, 2026, the breach was identified by PNLD. By July 29, 2026, media outlets reported the incident, and by August 3, 2026, official statements and technical analyses were published. All affected parties were notified within days of the incident, and the ICO was informed. The investigation remains ongoing, with no official disclosure of the total number of affected individuals or the precise technical root cause as of the latest updates.
Threat Activity
The threat actor ExfilSquad claimed responsibility for the breach, posting data samples on a leak site and demanding payment from both the DfE and PNLD. The group’s tactics are consistent with data extortion operations, focusing on the exfiltration of sensitive contact information and leveraging it for ransom demands. There is no evidence of ransomware deployment, malware use, or destructive activity.
Technical analysis suggests that the attackers exploited a misconfigured Microsoft Power Platform/Power Pages portal, which allowed anonymous access to backend Dataverse tables. This method aligns with recent campaigns targeting public-facing applications with excessive permissions. The attackers did not move laterally within the network or escalate privileges beyond the initial access point.
The primary impact of the breach is the exposure of contact information, which increases the risk of targeted phishing and social engineering attacks. The attackers’ publication of data samples and ransom demands further underscores the extortion-focused nature of the campaign. Attribution to ExfilSquad is based on their public statements and the matching of leaked data to the compromised information, but no technical artifacts directly link the group to the breach.
Mitigation & Workarounds
The following mitigation steps are recommended, prioritized by severity:
Critical: All organisations using Microsoft Power Platform/Power Pages should immediately review and restrict anonymous user access to backend Dataverse tables and APIs. Ensure that only authenticated and authorized users can access sensitive data.
High: Conduct a comprehensive audit of all public-facing applications for misconfigurations, excessive permissions, and exposed APIs. Remediate any identified issues promptly.
High: Notify all affected individuals and organisations, providing guidance on recognizing and reporting phishing and social engineering attempts that may leverage the exposed contact information.
Medium: Monitor for suspicious activity targeting affected email addresses, including phishing campaigns and unauthorized access attempts.
Medium: Engage with law enforcement and relevant regulatory bodies, such as the Information Commissioner’s Office (ICO), to ensure compliance with data protection requirements and support ongoing investigations.
Low: Review and update incident response and communication plans to address data breach scenarios involving third-party platforms and cloud services.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated before enforcement. These IOCs are derived from public reporting and official disclosures; no malware hashes or C2 infrastructure were identified.
Type | Indicator | Reported (date) | Source
|
Domain | westyorkshire[.]police[.]uk | 03/08/2026 | https://www.pnld.co.uk/~/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f |
Domain | www[.]askthe[.]police[.]uk | 03/08/2026 | https://www.pnld.co.uk/~/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f |
pnlddata[@]westyorkshire[.]police[.]uk | 03/08/2026 | https://www.pnld.co.uk/~/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f |
References
PNLD Official Disclosure (03/08/2026): https://www.pnld.co.uk/~/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f
The Hacker News (03/08/2026): https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
The Guardian (29/07/2026, amended 30/07/2026): https://www.theguardian.com/technology/2026/jul/29/department-for-education-police-hackers-cybercrime
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organisations identify, assess, and monitor risks associated with external vendors and digital supply chains. Our platform enables continuous visibility into third-party exposures, supports evidence-based risk assessments, and facilitates rapid response to emerging threats. For questions or further information, please contact us at info@rescana.com.



