More than 100,000 police officers, criminal justice professionals and other users have had their contact information exposed following a cyberattack against the Police National Legal Database (PNLD), a legal reference service used by police forces across England and Wales. The organisation says the breach affected contact details but did not expose operational policing data or confidential case information.
PNLD confirmed it detected the incident on 26 July and has since launched an investigation with assistance from external cybersecurity specialists and the National Crime Agency (NCA). The Information Commissioner’s Office (ICO) has also been notified, and organisations whose staff use the service have been informed of the incident.
According to PNLD, the compromised information includes names, email addresses and organisational affiliations belonging to police officers, police staff, criminal justice professionals and government partners who use the platform. The organisation also said contact details submitted through its public Ask the Police website by members of the public who sent questions were among the affected data.
The service stressed that it does not store confidential records relating to victims, witnesses or offenders and said there is currently no evidence that those types of information were accessed. It also stated that investigators have not identified signs that passwords or other authentication credentials were compromised during the intrusion.
PNLD provides legal guidance and operational reference material to all 43 Home Office police forces in England and Wales, as well as the British Transport Police, and has been in use for more than 30 years. Its public-facing Ask the Police service allows members of the public to submit policing and legal questions and access published guidance.
After the breach became public, the newly emerged ExfilSquad extortion group claimed responsibility and published sample records on its leak site. The group alleges it stole approximately 1.9 GB of data containing around 135,000 contact records and has threatened to release additional information unless its demands are met. Those claims originate solely from the attackers and have not been independently verified.
Although PNLD has acknowledged that contact information was exposed, it has not attributed the attack to ExfilSquad or disclosed how the attackers gained access to its systems. The organisation has also not confirmed the amount of data the group claims to possess.
ExfilSquad has recently surfaced online with claims involving several public and private sector organisations, but many of those alleged breaches have not been confirmed by the named victims. In the case of PNLD, the cyberattack itself has been confirmed, while investigators continue working to determine the full scope of the incident and assess the accuracy of the threat group’s claims regarding the data allegedly stolen.
