U.K. Police and Government Contact Details Exposed in PNLD Dark Web Leak
The Police National Legal Database (PNLD) has confirmed that names, organisations, and work email addresses belonging to police officers, government partners, and criminal justice professionals were stolen and published on the dark web, according to The Hacker News. The incident was identified on July 26. A threat group called ExfilSquad listed PNLD on its leak site the same day, though PNLD has not formally attributed the attack to the group.
Some names and email addresses from people who submitted questions through the Ask the Police public service were also caught up in the leak. That detail matters: a phishing (a deceptive email designed to steal credentials or trick someone into clicking a malicious link) attempt addressed to a named police officer looks far more convincing than a generic one.
PNLD has stated no passwords or security credentials were taken. The organisation supports all 43 Home Office police forces and reported over 108,000 registered police users in its 2025–26 summary. As of August 3, no victim count has been confirmed.
Cybersecurity firm VenariX has assessed the likely method as misconfigured Microsoft Power Pages (a Microsoft tool for building public-facing websites connected to internal data). If the Anonymous Users role was granted broad access to the underlying data tables, anyone visiting the site could have read records without logging in. That hypothesis has not been confirmed for PNLD specifically.
PNLD is working with the National Crime Agency and the Information Commissioner's Office.
What to do: If you submitted a question through Ask the Police, check your email for guidance from PNLD. Be cautious of any unexpected emails referencing your name alongside law enforcement topics — even from addresses that look official. If in doubt, do not click any links; go directly to the sender's known website instead.
Sources

