ExfilSquad Leaks Contact Data of 100,000 UK Police Officers

ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Table of Contents
    Add a header to begin generating the table of contents

    The Police National Legal Database (PNLD) has confirmed that police, government, and customer contact information was compromised and published on the dark web, after the ExfilSquad data extortion group claimed the theft of roughly 135,000 contact records. The exposed material includes the names, organizations, and work email addresses of police officers, staff, criminal justice professionals, and government partners, plus the names and email addresses of people who submitted questions through the Ask the Police website.

    The group says it stole 1.9 GB of data covering approximately 114,000 PNLD subscribers and 21,000 Ask the Police users, and it has demanded a ransom in exchange for not releasing the remaining data. PNLD said there is no evidence that passwords or other security credentials were compromised. The intrusion was identified on July 26, the same day ExfilSquad listed PNLD on its leak site.

    What the Police National Legal Database Holds and What It Does Not

    PNLD is a legal-information service used for more than 30 years by the 43 Home Office police forces in England and Wales plus the British Transport Police. It is not the Police National Computer or the Police National Database, and it does not hold confidential victim, witness, or offender information. The distinction matters because the breach exposes a contact directory rather than criminal intelligence, but that directory still names thousands of serving officers in a way that can be weaponized.

    ExfilSquad’s Leak-Site Claim and the Demand for the Remaining Data

    ExfilSquad listed PNLD on its leak site and published sample data while demanding a ransom. The group is the same one that recently claimed an attack on semiconductor firm Analog Devices. As of August 3, PNLD had not disclosed how many people were affected, when the intrusion began, or how access was obtained.

    The VenariX Analysis Points to a Power Pages Misconfiguration Pattern

    VenariX reviewed samples from 11 of ExfilSquad’s 15 claimed victims and found Dataverse-consistent structures across all 11. It assessed a likely campaign-level path as a public Microsoft Power Pages site with broad Anonymous Users access to Dataverse tables, combined with an enabled Power Pages Web API or legacy OData feed. VenariX stressed the Power Pages link is a hypothesis, not a confirmed PNLD root cause, and no ransomware, malware, lateral movement, or software-vulnerability exploitation was found in the examined campaign material.

    Why the Hypothesis Matters for Other Dataverse-Based Organizations

    If the misconfiguration pattern holds, the implication extends beyond PNLD: any organization running public Power Pages sites with permissive Anonymous Users permissions on Dataverse tables could be exposed through the same route. VenariX recommends Power Pages operators review Anonymous Users table permissions, Web API settings, and legacy OData feeds, and validate access from an unauthenticated browser session.

    Response From PNLD and the Phishing Risk to Named Officers

    PNLD has contacted all affected organizations, notified the Information Commissioner’s Office, and is working with the National Crime Agency and specialist cybersecurity firms. UK government guidance notes that the exposure of names and email addresses could make phishing messages targeting named officers more convincing, adding a pressure point for officers and criminal-justice professionals who now face targeted social engineering built on their real contact details.

    The unanswered questions — how many people are affected, when access began, and how the data was taken — leave affected organizations and individuals with limited ability to assess their own exposure. For the wider public sector, the incident illustrates that even a low-sensitivity contact directory, if misconfigured, can seed a phishing campaign aimed at a government’s most sensitive professional population. Whether the VenariX pattern holds will determine if this is an isolated incident or a problem shared by other Dataverse-backed government services.

    The 30-year history of the service and its reach across all 43 Home Office forces mean the exposed directory describes a large share of the UK’s policing establishment. For the officers and criminal-justice professionals named, the practical risk is that the leaked records become a permanent fixture of the extortion group’s archives, usable in campaigns long after the initial disclosure fades from the news.

    Related Posts