Home / Technology

Photo of software, tablet, 3D printer
Image: Wikipedia
Technology

UK Police Legal Database Breach Exposes Data of Over 100,000 Workers

WireByte Staff · August 4, 2026

A cyberattack on the UK's Police National Legal Database exposed the personal information of more than 100,000 criminal justice professionals. Threat group ExfilSquad claimed responsibility, publishing 1.9 GB of stolen records on the dark web after a ransom demand. While passwords remain secure, the breach highlights ongoing vulnerabilities in national law enforcement digital infrastructure.

Key points

  • The Police National Legal Database, a UK organization providing legal information to law enforcement, suffered a weekend cyberattack affecting over 100,000 criminal justice professionals.
  • Threat group ExfilSquad claimed responsibility for the incident, publishing 1.9 GB of stolen records on the dark web and demanding a ransom.
  • Exposed information includes names, organizations, and work email addresses belonging to police officers, staff, government partners, and customers.
  • Database administrators confirmed that passwords and security credentials were not compromised during the unauthorized access.
  • The organization hired cybersecurity specialists, notified the National Crime Agency and the Information Commissioner's Office, and contacted affected parties.

A major cyberattack has targeted the United Kingdom's Police National Legal Database (PNLD), resulting in the exposure of personal data belonging to more than 100,000 criminal justice professionals. The breach occurred over a weekend and compromised sensitive work-related information across the law enforcement sector.

A threat actor identifying as ExfilSquad claimed responsibility for the attack. The group published a 1.9 GB archive of stolen records on the dark web and demanded an unspecified ransom. The leaked material includes names, associated organizations, and professional email addresses of police officers, internal staff, government partners, and paying customers.

In response to the incident, PNLD officials stated that an investigation confirmed no passwords or core security credentials were compromised. The organization immediately engaged external cybersecurity specialists to assess the damage and secure the remaining infrastructure.

Authorities have escalated the response significantly. PNLD notified both the National Crime Agency (NCA) and the Information Commissioner's Office (ICO). Affected organizations were contacted following the breach to receive guidance. The NCA has launched a formal investigation into ExfilSquad and the dissemination of the stolen data.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.