PNLD breach exposes UK police and justice-sector contact data
PNLD confirmed publication of names, organisations and work email addresses. We separate the official notice from ExfilSquad claims and explain response steps.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 3 August 2026
- READING TIME
- 9 min read
- TOPIC
- Threats and Incidents
The Police National Legal Database (PNLD) has confirmed an incident in which contact data belonging to police officers, staff and other justice-sector professionals was compromised and published on the dark web. The breach also affects some users of the public Ask the Police service.
Scope must be described precisely. PNLD’s notice confirms names, organisations and work email addresses. It has found no evidence that passwords or other authentication credentials were compromised. PNLD is not a crime-recording system and says it does not hold confidential information about victims, witnesses or offenders.
What is known—and what is not confirmed
The incident was identified on Sunday, 26 July. PNLD is working with cybersecurity specialists and the UK’s National Crime Agency, has notified the Information Commissioner’s Office, and contacted affected organisations.
The ExfilSquad extortion group claimed the attack and alleges it obtained 1.9 GB containing roughly 135,000 records: 114,000 PNLD subscribers and 21,000 Ask the Police users. BleepingComputer reports that the group published a sample. PNLD has not attributed the intrusion to that actor or disclosed the access vector. The numbers are therefore criminal claims, not the result of a completed investigation.
For Ask the Police, PNLD confirms that some names and email addresses belonging to people who previously submitted a question were published. Identified individuals received an email with further information.
“Contact data only” still carries risk
A work address, name and organisation are enough to construct a credible pretext. An attacker can impersonate a manager, support desk, the NCA, PNLD or a government partner. Publishing professional affiliations may also increase the risk of harassment, doxing and targeted spear phishing for police and justice staff.
The absence of passwords does not remove the need to act. Attackers may:
- solicit a password reset or MFA code while citing the real incident;
- send a fake “PNLD notice” linked to a credential page;
- correlate work data with phone numbers and social accounts;
- target a less-protected partner by abusing a known police relationship;
- intimidate people whose role has been exposed.
Guidance for people and organisations
Notice recipients should use only official PNLD or employer channels. Do not sign in through an unexpected message or provide an MFA code to a caller. Treat urgent account verification, payment-detail changes and document requests with additional caution.
Organisations should give staff one verifiable source of information, strengthen detection for PNLD lookalike domains and monitor account-recovery attempts. Higher-risk accounts should use phishing-resistant MFA, controlled enrolment of new methods and stronger helpdesk verification.
Incident teams should maintain two workstreams: technical investigation of access and exfiltration, and protection of the people whose details were published. Our incident-response plan and identity-theft protection guide provide a practical framework.
Primary facts versus Breachroad analysis
PNLD confirms the published data types, discovery date, work with the NCA and ICO notification. The 135,000-record count, 1.9 GB volume and ExfilSquad attribution come from the group and media reporting. The access vector remains undisclosed.
Breachroad’s conclusion is to treat exposed organisational relationships as operational spear-phishing data even without passwords. Cybersecurity and phishing training can prepare staff and helpdesks for follow-on attacks, while an IT security audit can assess identity protection, monitoring and communications readiness.


