over 108,000
The UK's Police National Legal Database (PNLD), a key information resource for law enforcement, has confirmed a significant data breach. The incident, first identified on July 26, 2026, resulted in the exfiltration and subsequent publication of user contact information on the dark web. The exposed data includes the names, work email addresses, and associated organizations of over 100,000 registered users. These users comprise police officers, police staff, criminal justice professionals, and government partners across all 43 Home Office forces in the UK. The breach also affected members of the public who used the "Ask the Police" service. The extortion group ExfilSquad has been linked to the attack. While the PNLD asserts that no passwords were compromised, the incident exposes law enforcement personnel to heightened risks of targeted phishing and social engineering attacks.
The PNLD is a subscription-based service that provides legal guidance and does not hold confidential information about victims or offenders. However, the breach of its user database is highly sensitive. The attackers managed to access and exfiltrate a user list containing full names, official email addresses, and the specific police force or government agency the individual works for.
The threat actor, reportedly ExfilSquad, then published this data on the dark web. The primary risk now is not direct system compromise, but the use of this data for secondary attacks. Threat actors can craft highly convincing spear-phishing emails that appear to originate from a legitimate colleague or partner agency, leveraging the names and organizations from the breach. This could be used to steal credentials, deliver malware, or gain a foothold in secure government and police networks.
Some reports have speculated that an exposed Microsoft Power Apps portal may have been the entry point, but this has not been officially confirmed by PNLD.
While the exact vector is unconfirmed, a misconfigured or vulnerable web application is the most likely cause.
T1190 - Exploit Public-Facing Application.T1530 - Data from Cloud Storage Object if using a cloud backend, or T1005 - Data from Local System for an on-premise database.T1048 - Exfiltration Over Alternative Protocol.Even without password exposure, the impact of this breach is significant.
No specific indicators of compromise were mentioned in the provided source articles.
Organizations affected by this breach should focus on detecting follow-on phishing attacks:
log_sourceotherdomainExfilSquad claims responsibility for the PNLD breach, demanding ransom and leaking samples of 135,000 police and justice personnel records. West Yorkshire Police and NCA are investigating.
Enforcing MFA is the most effective control to mitigate the risk of credential compromise from follow-on phishing attacks.
Train users to identify and report sophisticated phishing emails that may leverage the breached data.
Securely configure web applications and platforms like Microsoft Power Apps to prevent unauthorized data exposure.
For all organizations whose personnel were exposed in the PNLD breach, the highest priority mitigation is to enforce phishing-resistant Multi-Factor Authentication (MFA) across all services, especially email and remote access systems. Since the breach enables highly targeted spear-phishing, stolen passwords are a likely outcome. MFA acts as a critical backstop, preventing an attacker from using a compromised password to gain access. Organizations should prioritize FIDO2/WebAuthn-based authenticators or number matching with push notifications over less secure methods like SMS or simple push approvals.
For the breached entity (PNLD) and others using similar platforms, this incident highlights the need for rigorous application configuration hardening. If a Microsoft Power Apps portal was the vector, it was likely due to misconfigured table permissions, which can inadvertently expose data to unauthenticated users. Administrators must review and lock down permissions for all data tables, ensuring that only authenticated users with the proper roles can access sensitive information. Anonymous access should be disabled for any data that is not explicitly public. Regular configuration audits using CSPM or specialized Power Platform security tools are essential to prevent this type of data leakage.
The data breach at PNLD is first identified.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.