UK Police Legal Database Breach Exposes 100,000+ Officers as ICO and NCA Step In

The Police National Legal Database has confirmed contact details of officers and criminal justice staff were stolen, with the ExfilSquad group claiming 135,000 records and demanding a ransom.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial image, full-frame 16:9, of a dimly lit hospital corporate office at night with rows of empty desks, a single monitor glowing with abstract c
Share

Key points

  • The Police National Legal Database (PNLD) detected an intrusion on Sunday 26 July 2025 and has now confirmed the theft of contact records.
  • Stolen data includes full names, employer, and email addresses of police officers, staff, and criminal justice professionals across the 43 Home Office forces in England and Wales plus British Transport Police.
  • An extortion group calling itself ExfilSquad claims to have taken 1.9 GB of data covering roughly 135,000 records, including 21,000 users of the public 'Ask the Police' site.
  • PNLD says no passwords were taken, and no records on victims, witnesses, or offenders were held on the affected systems.
  • The National Crime Agency is assisting the investigation and the Information Commissioner's Office (ICO) has been notified, triggering the 72-hour breach notification duty under Article 33 UK GDPR.

The Police National Legal Database, an online legal reference used by every Home Office force in England and Wales for more than three decades, has confirmed a cyberattack exposed the contact details of well over 100,000 officers and criminal justice workers.

PNLD says it spotted the intrusion on 26 July. The extortion crew ExfilSquad later claimed responsibility, published sample data, and demanded payment to withhold the rest. The breach was first reported by BleepingComputer.

What exactly was taken?

Contact information, not case files. PNLD says the exposed fields are full names, the organisation the person works for, and work email addresses. That covers police officers, police staff, criminal justice professionals, and government partners who use the subscriber service.

Also caught up in the theft: the names and email addresses of members of the public who submitted questions through 'Ask the Police', PNLD's public-facing Q&A site.

PNLD has stated that no passwords or other security credentials appear to have been taken. Crucially, the database does not hold confidential information on victims, witnesses, or offenders, so operational casework is not implicated.

Fact Detail
Intrusion detected 26 July 2025
Records claimed stolen ~135,000
Data volume claimed 1.9 GB
PNLD subscribers affected ~114,000
Ask the Police users affected ~21,000
Group claiming responsibility ExfilSquad

What are the regulators doing?

PNLD has notified the ICO, the UK's data protection regulator, and the National Crime Agency is providing investigative support. Notification to the ICO within 72 hours of awareness is the statutory trigger under Article 33 of the UK GDPR where a personal data breach is likely to cause risk to individuals.

Affected organisations, meaning the forces and partner bodies whose staff details sit in the database, were contacted in the days after the incident. PNLD has not publicly attributed the intrusion beyond confirming ExfilSquad's leak and has not disclosed the initial access method.

Whether the ICO opens a formal investigation, and whether it treats PNLD's controller-processor arrangements with the individual forces as in scope, will shape any later enforcement action. The ICO's published enforcement approach reserves monetary penalties for serious failures under Section 155 of the Data Protection Act 2018.

Should officers and members of the public worry?

The practical risk is targeted phishing, where criminals send fake emails designed to look legitimate in order to steal passwords or plant malware. A stolen list of verified police and criminal justice email addresses is an unusually clean phishing list.

Officers and staff on affected forces should treat any unexpected email referencing PNLD, legal updates, or account resets with suspicion, and verify through internal channels before clicking. Members of the public who have ever submitted a question through Ask the Police should watch for scam emails that name them personally.

There is no indication passwords were taken, so a mass account takeover is not the immediate concern. Social engineering is.

Who is ExfilSquad?

ExfilSquad is a data extortion crew that steals data and threatens publication rather than encrypting systems. The same name recently surfaced in a claimed intrusion at the American semiconductor firm Analog Devices. Attribution beyond the group's own claims has not been made public in the PNLD case.

PNLD says its investigation, supported by external cybersecurity specialists and the NCA, is continuing.

© 2026 Threat Vectr