UK Police Legal Database Breach Exposes 100,000+ Officers as ICO and NCA Step In

The Police National Legal Database has confirmed contact details of officers and criminal justice staff were stolen, with the ExfilSquad group claiming 135,000 records and demanding a ransom.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Photoreal editorial image, full-frame 16:9, of a dimly lit hospital corporate office at night with rows of empty desks, a single monitor glowing with abstract c
Share

Key points

  • The Police National Legal Database (PNLD) detected an intrusion on Sunday 26 July 2025 and has confirmed the theft of contact records.
  • Stolen data includes full names, employer and email addresses of police officers, staff and criminal justice professionals across the 43 Home Office forces in England and Wales plus British Transport Police.
  • ExfilSquad claims to have taken 1.9 GB of data covering roughly 135,000 records, including 21,000 users of the public 'Ask the Police' site.
  • PNLD says no passwords were taken and no records on victims or offenders were held on the affected systems.
  • The National Crime Agency is assisting the investigation and the ICO has been notified under the UK GDPR's breach notification requirement.

The Police National Legal Database, an online legal reference used by every Home Office force in England and Wales for more than three decades, has confirmed a cyberattack exposed the contact details of well over 100,000 officers and criminal justice workers.

PNLD says it spotted the intrusion on 26 July. ExfilSquad later claimed responsibility, published sample data and demanded payment. We first covered the dark web publication of that data on 3 August. This story covers the formal confirmation and regulatory response.

What exactly was taken?

Contact information, not case files. Exposed fields are full names, the organisation the person works for, and work email addresses. That covers police officers, police staff, criminal justice professionals and government partners who use the subscriber service.

Also caught up in the theft: names and email addresses of members of the public who submitted questions through 'Ask the Police', PNLD's public-facing Q&A site.

No passwords or other security credentials appear to have been taken. The database doesn't hold confidential information on victims or offenders, so operational casework isn't implicated.

Fact Detail
Intrusion detected 26 July 2025
Records claimed stolen ~135,000
Data volume claimed 1.9 GB
PNLD subscribers affected ~114,000
Ask the Police users affected ~21,000
Group claiming responsibility ExfilSquad

What are the regulators doing?

PNLD has notified the ICO, the UK's data protection regulator, and the NCA is providing investigative support. UK GDPR requires organisations to notify the ICO when a personal data breach is likely to cause risk to individuals. Affected organisations were contacted in the days after the incident. PNLD hasn't publicly attributed the intrusion beyond confirming ExfilSquad's leak and hasn't disclosed the initial access method.

Whether the ICO opens a formal investigation, and whether it treats PNLD's controller-processor arrangements with individual forces as in scope, will shape any later enforcement action. Monetary penalties are reserved for serious failures under data protection law, so the enforcement bar is real but not automatic.

Should officers and members of the public worry?

The immediate risk is phishing: criminals sending fake emails designed to steal passwords or plant malware. A verified list of police and criminal justice email addresses is an unusually clean target for that kind of attack. It's not a theoretical risk.

Officers and staff should treat any unexpected email referencing PNLD, account resets or legal updates with suspicion and verify through internal channels before clicking. Members of the public who ever submitted a question through Ask the Police should watch for scam emails that name them personally.

There's no indication passwords were taken, so mass account takeover isn't the immediate concern. Social engineering is.

Who is ExfilSquad?

ExfilSquad steals data and threatens publication rather than encrypting systems. The group recently surfaced in a claimed intrusion at Analog Devices, the Massachusetts chip-maker. Attribution beyond ExfilSquad's own claims hasn't been made public in the PNLD case.

This breach lands in a period of sustained pressure on UK public-sector data: our Department for Education story from 1 August reported 607,000 records exposed across two government education portals. Two incidents involving public-sector contact databases in a fortnight is the pattern worth watching, not just the individual headcount.

PNLD says its investigation, supported by external cybersecurity specialists and the NCA, is continuing.

© 2026 Threat Vectr