A U.K. police database breach has exposed the personal information of over 100,000 law enforcement officers, justice staff, criminal justice professionals, officials, and customers.
The breach affected the U.K.’s Police National Legal Database (PNLD), a West Yorkshire Police-operated legal information resource that serves 43 Home Office police forces, enabling them to apply the law correctly. It also hosts the public-facing “Ask the Police” platform that answers the most frequently asked legal and policing questions.
The data breach surfaced on July 26 after cybercrime gang ExfilSquad claimed it had stolen 135,000 records and published samples online as proof.
U.K. police database breach leaks personal information
The police database hack exposed names, work email addresses, and organizations of law enforcement officers, criminal justice professionals, police staff, and government partners.
Similarly, individuals who submitted questions via the public-facing “Ask the Police” platform had their names and email addresses leaked. However, the data breach did not leak account login credentials or sensitive investigative information related to victims, witnesses, or offenders.
PNLD has confirmed the data breach but has yet to attribute the police database hack to any threat actor and has not disclosed the attack vector exploited. Phishing and software vulnerabilities are among the leading causes of data breaches.
The National Crime Agency and the Information Commissioner’s Office have been notified of the police database breach and are investigating the incident. PNLD operators have also hired external cybersecurity experts to investigate and respond to the breach. All organizations affected by the police database hack have also been notified.
“All affected organizations were contacted in the days following the incident and provided with further information and guidance,” the agency stated. “The Information Commissioner’s Office (ICO) has also been notified.”
Impacted victims whose email addresses were leaked should also be on the lookout for potential phishing attempts that try to steal their sensitive information, including credit card numbers.
“A database of 135,000 verified identities across law enforcement and criminal justice, with employing organizations attached, is not contact information in the ordinary sense,” said Seemant Sehgal, Founder & CEO, BreachLock. “That combination tells an adversary exactly who works where, in what capacity, and how to reach them directly. The downstream risk to be concerned about here is social engineering, targeted harassment, and covert approaches to personnel who would otherwise be a lot more difficult to identify and map.”
Cyber extortion gang ExfilSquad linked to U.K. police database hack
Cyber extortion gang ExfilSquad has claimed responsibility for the U.K. police database breach. It claims to have stolen 1.9 GB of data containing 135,000 records, consisting of 114,000 law enforcement and justice system professional records and 21,000 personal details of people who submitted questions via the “Ask the Police” system. Nevertheless, PNLD has not independently confirmed how many victims were affected.
Meanwhile, ExfilSquad has demanded an unspecified ransom to avoid publishing the stolen information online. The group warns that when the stolen information is leaked online, the damage is irreversible.
ExfilSquad is a minor league cyber extortion gang. The cybercrime gang was linked to the U.K.’s Department of Education (DfE) data breach that leaked over 600,000 records related to helpdesk and Turing Scheme, and Analog Devices, a semiconductor company.
Other data breach claims by the cybercrime gang include the City of Houston and City of Atlanta breaches, Newcastle University, and Wesco International.
ExfilSquad also claims to have breached Microsoft and stolen 13 GB of data consisting of internal support tickets, password hashes, and access permissions. PNDL also uses Microsoft Power Platform, a no-code platform that also helps users analyze data, but no evidence suggests that the attackers exploited the system to gain access.
“A simple misconfiguration in a Microsoft Power Pages portal was the impetus for this breach,” said Denis Calderone, CTO, Suzu Labs. “PNLD’s Anonymous Users web role had read access to backend Dataverse tables, which means the subscriber database was queryable through a standard API call by anyone who visited the site without logging in.”
“And similar to the open S3 bucket issue that was so prevalent a few years ago, ExfilSquad didn’t need to deploy malware or exploit a zero-day, they just had to hunt for misconfigured endpoints. And what was sitting behind those endpoints happened to be the names, force assignments, and work emails of 135,000 police officers, CPS prosecutors, and criminal justice professionals across all 43 forces in England and Wales,” added Calderone.

