VMTech
Discuss a project

UK police and government contact details exposed in PNLD breach

UK police and government contact details exposed in PNLD breach

The Police National Legal Database has confirmed that names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers were compromised and published on the dark web. PNLD identified the incident on July 26, 2026, but had not disclosed the number of affected people or the volume of data by August 3.

Some names and email addresses of people who submitted questions through Ask the Police were also exposed. PNLD said there was no evidence that passwords or other security credentials had been compromised.

The service has contacted affected organisations and sent guidance to affected Ask the Police users. It also notified the Information Commissioner's Office and is working with the National Crime Agency and specialist cybersecurity organisations.

What the database does and does not contain

PNLD supplies legal information, products and services to UK police forces and criminal justice organisations. It is neither the Police National Computer nor the Police National Database, does not record crimes, and does not hold confidential information about victims, witnesses or offenders.

Its 2025-26 annual summary recorded 108,429 police registrations and support for all 43 Home Office police forces. That figure describes the service's user base and must not be interpreted as the number of breach victims.

The release of named professional contact details can still improve the credibility of targeted phishing. The risk reflects borrowed trust in cyberattacks because attackers can use familiar identities and organisational context to make requests appear legitimate.

A Power Pages theory remains unproven

PNLD said in its 2023-24 annual summary that it uses Microsoft Power Platform technology. The breach-notice page also referenced assets on Microsoft's content.powerapps.com domain, corroborating the platform connection without establishing how the data was accessed.

VenariX reviewed samples linked to 11 of ExfilSquad's 15 claimed victims and found structures consistent with Dataverse in all 11. In the Houston case, it verified that a public portal returned records without authentication and that those records matched data published by the group.

At campaign level, VenariX assessed a broadly accessible Anonymous Users role on a public Power Pages site as a likely route, combined with an enabled Power Pages Web API or legacy OData feed. Microsoft documentation states that giving the Anonymous Users role access to a table exposes its data to site visitors, while the /_api interface follows each web role's table permissions.

However, neither PNLD nor VenariX identified a PNLD-specific endpoint, permission, API route or supporting log. VenariX also cautioned that the evidence does not establish the same route for every victim. The theory is therefore a configuration pattern to test, not a confirmed explanation for this breach.

Controls businesses can verify now

ExfilSquad listed PNLD on its leak site on July 26, but PNLD has not attributed the incident to the group. VenariX found no evidence of ransomware, malware, lateral movement or exploitation of a software vulnerability in the campaign material it examined.

Microsoft offers a tenant-level control that prevents unauthenticated users from reading Dataverse data while allowing public form submissions. VenariX advises operators to review Anonymous Users table permissions, Web API settings and legacy OData feeds, then test access in an unauthenticated browser session.

For businesses, the immediate implication is twofold: warn personnel that exposed professional details may support convincing phishing, and independently audit public portal access rather than treating platform use alone as proof of the breach route.

#databreach#cybersecurity#phishing#dataverse
Open analytics
On the site 1 views
min read 4 05.08.2026
Instagram

UK police and government contact details exposed in PNLD breach

Open the post on Instagram ↗