The full names and work contact details of more than 100,000 UK police officers and staff appeared on the dark web after a breach of the Police National Legal Database (PNLD), UK newspapers reported on 2 August 2026. Extortion group ExfilSquad had already advertised roughly 135,000 law-enforcement contact records from the same system. The National Crime Agency told The Times that limited personal details of some NCA officers may have been published because of the PNLD incident, and the National Cyber Security Centre said it is supporting law enforcement on the case.
Canonical BreachHistory record: Police National Legal Database ExfilSquad breach.
What happened in the PNLD data breach
PNLD is the day-to-day legal assistance database used across Home Office police forces in England and Wales. Officers look up guidance there constantly. That ubiquity is exactly why a contact extract is dangerous: every address is a working professional mailbox tied to a named person and a force area.
ExfilSquad’s leak-site summary, mirrored on ransomware monitors, described about 135k law enforcement contact records with first/last name, email and police force area. The Times and The Telegraph reported that more than 100,000 officers and staff had details leaked, and that the compromised pool included officials connected to the Ministry of Defence, Home Office, National Crime Agency and Crown Prosecution Service — not because those departments’ classified case files sat in PNLD, but because their people use the shared legal database.
FutureScot reported that PNLD, hosted by West Yorkshire Police, referred itself to the Information Commissioner. The Record noted the Home Office declined to comment while NCSC acknowledged support for responders. That combination — press scale figures, NCA acknowledgment, ICO referral — is enough to treat the PNLD data breach as a confirmed incident with a press/actor scale still labelled carefully in our catalog.
What data was exposed — and what was not
Coverage consistently describes names, employing forces/organisations and work email addresses for officers and criminal-justice staff. Some reporting also mentions members of the public who used the Ask the Police service. PNLD has said the database does not hold confidential victim, witness or offender investigation material. Believe that distinction. Then ignore the comforting conclusion that “low immediate risk” means “nothing to worry about.”
Contact data is the starter kit for targeted phishing. An attacker who knows your force, your role-adjacent mailbox and the fact that you use PNLD can write a password-reset lure that lands. Multi-factor authentication helps until an adversary-in-the-middle kit steals the session. That is the realistic abuse path after this UK police data breach — not a sudden dump of sealed case files.
Timeline: ExfilSquad, DfE, then PNLD in the headlines
- ~26 July 2026: ExfilSquad listings for UK Department for Education (~607,000 data lines from help-desk/Turing Scheme portals) and PNLD (~135,000 contacts) surface on leak monitors.
- Late July: DfE speaks to risk and lines-of-data framing; NCA investigates the education incident; PNLD/West Yorkshire refer to ICO.
- 2 August 2026: The Times / Telegraph detail 100,000+ police staff contacts on the dark web; NCA confirms some officer details published via the PNLD incident; Police Federation raises officer-safety concerns.
Read the DfE and PNLD events as sibling ExfilSquad campaigns in the same week, not as one mashed-together “government mega-breach.” BreachHistory keeps separate rows: UK DfE ExfilSquad and this PNLD record.
Who is at risk
Police officers and police staff whose work emails sat in PNLD — especially those who previously worked serious organised crime, firearms, or other high-risk roles where personal exposure has operational consequences. One staff member told The Times the leak was “very disconcerting” after past moves into safe houses.
NCA, CPS, Home Office and MoD personnel who used the shared legal database. The NCA’s careful wording (“limited personal details… may have been published”) is still an official acknowledgment that some of its people are in the spill.
Members of the public who contacted Ask the Police, if their names and addresses were in the extract described by secondary analysis.
Everyone else in UK policing email ecosystems should assume copycat phishing that name-drops PNLD, West Yorkshire hosting, or “mandatory legal-database MFA reset.”
Why 135,000 contacts beat 607,000 education lines for attackers
The DfE figure dominated early headlines because it is larger. Analysts noted the education extract looked thin per record, while the PNLD set was bulkier per person. More importantly, police and criminal-justice mailboxes are higher-value targets for coercion and credential theft. A wrong “reset your PNLD account” email to a detective is not the same problem as a wrong email to a school administrator — both are bad; one can get people hurt.
Tiff Lynch of the Police Federation called for proper cyber funding so forces are not soft targets. Jake Moore of ESET told UK press that government organisations are being seen as softer targets and that leaked contacts fuel personalised follow-up attacks. That is the plain reading of this Police National Legal Database breach.
What officials said
NCA: aware that limited personal details of a number of NCA officers may have been published on the dark web as a result of the PNLD incident. NCSC: supporting law enforcement colleagues on an incident affecting PNLD. Government spokespeople: dedicated cyber response capabilities; inappropriate to comment further on a live investigation. PNLD/West Yorkshire: ICO referral; messaging that investigation content is not in the database and immediate risk assessed as low regarding that class of data.
Hold both ideas at once: the content may not be case files, and the operational risk from contact exposure can still be serious.
Action items after the PNLD / UK police contacts leak
- If you are an officer or staff member, assume your work email and force affiliation may be public to criminals. Heighten personal OPSEC online.
- Treat any PNLD, “legal database,” West Yorkshire, or “force email migration” message as hostile until verified through known intranet channels — never via the email’s own links.
- Rotate work credentials where policy allows; ensure MFA is phishing-resistant where forces provide it.
- Report suspicious messages through your force’s security operations process immediately.
- Family members should be briefed that criminals may try WhatsApp pretexting using your name and force.
- Ask the Police users: watch for identity scams referencing a prior question you asked online.
- Do not engage ransom negotiators or pay “delisting” services.
- Follow force welfare guidance if you previously had protection arrangements — escalate to professional standards/welfare if the leak raises specific threats.
- Journalists should separate the 100,000+ staff framing from the ~135,000 record claim and cite both.
- Bookmark the BreachHistory PNLD page for stable sourcing as investigations continue.
Campaign context: ExfilSquad’s short, loud arrival
ExfilSquad is a relatively new extortion brand in mid-2026 coverage, claiming multiple Western victims in quick succession — including Analog Devices-related claims elsewhere in the catalog. Many listings remain unverified. PNLD and DfE are different because UK institutions and NCSC/NCA language put institutional flesh on the bones. Newcastle University was also named in ExfilSquad marketing (~440k applicant/student contacts claimed); that row stays labeled unverified until ncl.ac.uk attests counts.
Canonical record and sources
Catalog; The Times; The Telegraph; The Record; FutureScot; Ransomware.live listing.
Was I affected?
If you are a UK police officer or police staff member who used PNLD, or you work in NCA/CPS/Home Office/MoD roles that share that legal database, you are in the population newspapers and the NCA are talking about. The precise individual list is not public from BreachHistory — wait for force or agency notices. Public Ask the Police correspondents may also be in a subset of the extract.
What to do after a police contacts data breach
Prioritise phishing defence and personal safety hygiene over consumer credit freezes unless your notice lists home addresses or financial identifiers. Work email exposure is an operational security problem first. Credit freezes still help if home addresses of public users were included and you receive a specific notice saying so.
FAQ
How many people? Times: 100,000+ staff; actor/press monitors: ~135,000 contact records. Both figures appear in reputable coverage.
Who attacked? ExfilSquad claimed the listing; attribution beyond the brand name remains an active investigation matter.
Are case files leaked? PNLD says the database does not hold confidential victim/witness/offender investigation data.
Is this the same as the DfE hack? Related actor and week; different systems. Keep them separate when you search “ExfilSquad UK.”
Bottom line
The Police National Legal Database breach is a confirmed UK law-enforcement incident: ExfilSquad published contact-scale data, NCA acknowledged officer details in the spill, NCSC is supporting responders, and newspapers put 100,000+ officers and staff on the dark web. Treat PNLD-themed phishing as hostile, harden officer OPSEC, and follow force welfare channels while investigations continue.
For a durable summary that separates PNLD from the DfE twin incident, use the BreachHistory canonical pages and the primary outlets linked above — not anonymous “full dump” channels that recycle the same screenshots.
Further reading for practitioners
Security teams supporting fiduciaries, banks, or UK forces should map this incident into their existing playbooks rather than inventing a one-off process. Start from identity of the dataset, confirm whether your organisation appears in the affected population, then execute phishing defences and executive briefings in that order. Premature public statements that over-claim “no risk” age badly when secondary leaks appear months later.
Researchers comparing verified government disclosures to unverified leak-site marketing should keep Liechtenstein and PNLD in the first bucket. Actor brands still matter for hunting, but the cataloguing standard is attestation: a ministry statement, an NCA sentence, an ICO referral — not a Telegram screenshot alone.
If you are rebuilding vendor questionnaires after these stories, ask beneficial-ownership service providers and legal-database vendors how they detect bulk export, how quickly they can take a register offline, and how they notify controllers when the register itself is the crown jewel. Those questions were theoretical last month. They are operational now.
Finally, keep language precise when you brief boards. “Approximately 31,000 legal entities” is not the same as “31,000 Liechtenstein citizens.” “More than 100,000 police officers and staff” is not the same as “every UK police investigation file.” Precision protects trust — the scarce resource after any public-sector data breach.
Boards should also schedule a follow-up in 90 days: ask whether notifications completed, whether phishing volume spiked against the affected population, and whether any secondary dump changed the field list. Breach stories end in the news cycle long before they end in the SOC ticket queue.
Individuals who want a single stable URL for colleagues can share the BreachHistory canonical pages rather than forwarding paywalled screenshots. That reduces link rot and keeps the verified-versus-claim distinction visible.
Operational footnote for incident responders: preserve original government and agency statements, capture the first-seen dates of leak-site listings, and avoid consolidating DfE and PNLD into a single ticket when the systems and data types differ. Cross-link them in your case notes, but keep containment and communications trees separate so the wrong population does not receive the wrong guidance. When you publish internal FAQs, lead with what was confirmed, what remains estimated, and what employees should do before lunch tomorrow — not with a history of ransomware brands. That discipline is how organisations stay credible after the second week of headlines.
For external counsel supporting beneficial owners or police staff associations, document the chronology with primary URLs, note which counts are government-attested versus press-estimated, and prepare clients for a long tail of social-engineering attempts that will cite these exact numbers. Attackers read the same articles. Your clients’ best defence is boring: out-of-band verification, MFA, and refusal to act on urgency manufactured by strangers.
Officer safety is not a metaphor
When a retail company loses emails, the main follow-on is phishing and account takeover. When a police legal database loses emails mapped to forces, the follow-on can include harassment of officers who have already lived under threat. That is why Federation comments framed the PNLD data breach as a safety issue, not only a GDPR issue.
Forces should revisit guidance for officers with existing protection concerns: what to do if doxxing attempts reference the leak, how to report, and how families should handle unexpected contact. Welfare and cyber need the same briefing deck for once.
Practical checklist for force IT and security teams
- Push a clear internal banner: PNLD-themed password resets arriving by email are presumed malicious.
- Ensure SOC playbooks include ExfilSquad / PNLD keywords in email gateway rules for 90 days.
- Offer optional personal OPSEC clinics for high-risk roles without stigma.
- Coordinate with West Yorkshire / PNLD operators on authentic notification channels so staff can recognise real messages.
- Separate communications about the DfE twin incident so school-facing staff are not flooded with police-specific advice and vice versa.
None of that requires waiting for a final forensic report. The contact data is already outside the building. Defence has to move at phishing speed.
Additional context for readers tracking 2026 public-sector incidents: keep primary sources bookmarked, distinguish verified government statements from actor marketing, and revisit this page when official field lists or notification counts are updated. Precision beats rumour when the dataset is as sensitive as beneficial ownership or police contacts.
Additional context for readers tracking 2026 public-sector incidents: keep primary sources bookmarked, distinguish verified government statements from actor marketing, and revisit this page when official field lists or notification counts are updated. Precision beats rumour when the dataset is as sensitive as beneficial ownership or police contacts.