A significant data breach has struck the United Kingdom's Police National Legal Database (PNLD), a centralized legal information service supporting all 43 Home Office police forces and other criminal justice agencies. The breach, identified on July 26, 2026, resulted in the theft of a database containing sensitive contact information, which was subsequently published on the dark web. The exposed data includes the names, work email addresses, and organizational affiliations of police officers, government staff, and other justice professionals. This incident creates a significant risk of highly targeted phishing and social engineering campaigns against UK law enforcement personnel. The investigation is ongoing, with a potential link to the Microsoft Power Platform technology used by the PNLD.
What Happened: An unauthorized actor gained access to and exfiltrated a database from the PNLD. The data was later found published on a dark web forum.
Data Exposed:
Attribution: The threat actor or method of intrusion has not been publicly disclosed.
The exact vector of the breach is still under investigation by the National Crime Agency (NCA). However, technical details point to a potential area of interest. The PNLD's annual summary mentioned its use of Microsoft Power Platform, and the breach notification page itself referenced assets hosted on Microsoft's content.powerapps.com domain. This suggests the breach may be related to a misconfiguration or vulnerability within a Power Apps application used by the PNLD. Misconfigurations in Power Apps, such as improper table permissions, have been a source of data exposure in other incidents.
This incident highlights the risk associated with low-code/no-code development platforms if not configured and secured correctly. A likely technique used by the attacker would be T1190 - Exploit Public-Facing Application if a vulnerability was present, or exploiting a misconfiguration related to public access settings.
No specific Indicators of Compromise (IOCs) were provided in the source articles.
UK government and law enforcement security teams should be on high alert for:
content.powerapps.com from unusual sourcesProperly configuring permissions within the Microsoft Power Platform to prevent anonymous or unauthorized data access is the primary mitigation.
Training police officers and staff to be vigilant for targeted spear-phishing attacks that may leverage the stolen data.
Enforcing MFA helps protect accounts even if credentials are stolen via a subsequent phishing attack.
The data breach at the Police National Legal Database (PNLD) was identified.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.