422/69 Wednesday, August 5, 2026

The Police National Legal Database (PNLD), a legal reference database used by all 43 Home Office police forces in England and Wales, has confirmed a data breach after contact information belonging to police officers, staff, and justice sector personnel was published on the dark web. The incident also affected Ask the Police, a public question-and-answer service hosted on the same platform. The exposed information includes names, organizations, and work email addresses of police officers, staff, justice sector professionals, and some customers. However, PNLD stated that there is currently no evidence that passwords or other security credentials were compromised.
PNLD stated that the security incident primarily affected the Police National Legal Database, which also provides the Ask the Police service. As a result, some names and email addresses of members of the public who had submitted questions through the service were also published on the dark web. PNLD clarified that the system provides legal information and services to police forces and justice organizations in the United Kingdom. It is not a criminal case record system and does not store sensitive information related to victims, witnesses, or offenders. PNLD has not yet disclosed the exact number of affected individuals, when the intrusion began, or the volume of data exfiltrated. Reports indicate that PNLD had 108,429 registered police users in its 2025–26 annual report.
UK law enforcement authorities are currently investigating the incident together with the National Crime Agency (NCA) and private-sector cybersecurity firms. The incident has also been reported to the Information Commissioner’s Office (ICO). Meanwhile, an extortion group named ExfilSquad listed PNLD on its leak site on July 26, although PNLD has not confirmed that the group was responsible for the incident. Cybersecurity firm VenariX analyzed data samples from victims claimed by ExfilSquad and found patterns consistent with Microsoft Dataverse, which may be related to a Microsoft Power Pages portal configuration that granted overly broad access to data. However, this remains an unconfirmed hypothesis for the PNLD case. Police officers and personnel whose information was exposed should remain alert for targeted phishing attacks that may use the leaked names, organizations, and work email addresses to support social engineering attempts.
