Breaking
Cyber CrimeDeveloping Story

PNLD Breach Exposes Police Contact Data

The Police National Legal Database confirms a data breach involving over 100,000 records of officers and legal professionals.

··3 hours ago·2 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

Unauthorized Access to Legal Databases

The PNLD says that an intrusion into its systems resulted in the unauthorized access of contact information belonging to police officers and various criminal justice professionals. The service, which has functioned as a central legal resource for over 30 years, supports the 43 Home Office police forces in England and Wales, alongside the British Transport Police.

Detection of the incident occurred on Sunday, July 26. Following the discovery, the entity known as the ExfilSquad data extortion group claimed responsibility for the breach. The organization is currently conducting an investigation into the event with the support of the National Crime Agency and external cybersecurity specialists.

Scope of the Stolen Records

The information compromised in the attack includes the full names, organizational affiliations, and email addresses of law enforcement staff and government partners. Additionally, the breach impacted the Ask the Police platform, which serves as a public-facing resource for legal queries. The names and email addresses of users who submitted questions through this specific site were also affected.

According to the group, the data consists of details concerning a large population of users. The following figures detail the extent of the compromised records as claimed by the threat actor:

  • 135,000 total records stolen by the group
  • 114,000 records belonging to PNLD subscribers
  • 21,000 records belonging to Ask the Police users
  • 1.9 GB of total data claimed to be exfiltrated

Security Status and Credentials

Despite the volume of contact information accessed, the service has reported that no passwords or security credentials were involved in the compromise. Furthermore, the database does not house sensitive information regarding victims, witnesses, or offenders, and the service has stated that no such data was impacted by the unauthorized access.

ExfilSquad has utilized sample data to support its claims regarding the intrusion. The group has also issued a ransom demand, seeking payment to prevent the release of the remaining stolen records. This threat actor was previously associated with an attack on Analog Devices.

Official Response and Notifications

“All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner’s Office (ICO) has also been notified,”

— PNLD

The service has confirmed both the breach and the subsequent publication of contact details by the threat actor. While the organization has notified the Information Commissioner’s Office, it has not yet provided information regarding the specific method of access or the identity of the attackers beyond the claims made by the group involved.

Implications for Institutional Security

The involvement of the National Crime Agency and the notification of the Information Commissioner’s Office indicate the regulatory and law enforcement attention currently focused on the event. For organizations utilizing centralized databases for professional resources, the situation underscores the importance of maintaining visibility over the security posture of third-party service providers. As the investigation progresses, the notification of affected organizations provides a channel for those parties to receive guidance on the incident.

#data breach#police#uk#cyber extortion#pnld

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories