On 26 July 2026, the Police National Legal Database (PNLD), the online legal reference service used for more than three decades by all 43 Home Office police forces in England and Wales and the British Transport Police, detected unauthorised access to its systems. A week later, the data extortion group ExfilSquad published a dark web listing claiming responsibility. By 3 August the scale was confirmed: PNLD acknowledged that the names, employers and work email addresses of more than 100,000 serving police officers, staff and criminal justice professionals had been accessed and, in part, published online.
ExfilSquad claims to have exported 1.9 gigabytes of data across two datasets: roughly 114,000 records belonging to PNLD subscribers, a figure PNLD itself has confirmed, and a further 21,000 records reportedly taken from users of its public-facing "Ask the Police" service, putting the group's total claimed haul at around 135,000 records. Among the confirmed subscriber population are 2,615 Crown Prosecution Service staff, 617 Home Office employees, 588 National Crime Agency staff and 402 Ministry of Defence personnel, several of them individuals whose work centres on serious organised crime.
PNLD has been explicit about one thing: it has found no evidence that a password, login or other credential was compromised. That single fact narrows the possibilities considerably. Whatever opened the door, whether a vulnerability in the platform itself or a weakness in one of the trusted third-party pipelines that feed it, the attacker did not need to guess or steal anyone's login to walk out with the database. The export itself, not any single act of authentication, is what turned an intrusion into a public leak.
The PNLD breach did not happen in isolation. Days earlier, the UK's Department for Education confirmed a separate ExfilSquad attack that exposed more than 607,000 records. Days after that, UK Government Investments disclosed that officials' internal details had sat exposed online for nearly 48 hours. Three public sector breaches, one group, one fortnight. ExfilSquad claims fifteen victims in total, including Microsoft and several other organisations, though not every claim has held up to scrutiny. The pattern is what matters: a single extortion operation is finding that the UK public sector's legacy systems and fragmented oversight open faster than they can be defended.
The defences that failed here were not weak by conventional standards. PNLD called in the National Crime Agency and external cybersecurity specialists within days. It notified every affected organisation and the Information Commissioner's Office. It ruled out credential compromise through forensic review, real diligence that most breached organisations never manage this quickly. None of it stopped the underlying database from being exported before anyone could confirm the action was legitimate.
A bulk export of 114,000 police officer records from a national legal database is an execution event, not a background process. Before a query or integration can pull tens of thousands of subscriber records out of a system like PNLD, a confirmation request should reach a named data controller, the individual accountable for that database, on their registered device. No confirmation, no export.
That control does not depend on knowing how the attacker got in, which is exactly what makes it durable against an intrusion PNLD itself still cannot explain. A stolen credential, a compromised integration or a vulnerability in a trusted pipeline can open a door. None of them can produce a biometric confirmation from the named authority on a device the attacker does not hold. The execution boundary holds regardless of the route the attacker took to reach it.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Toulas, B. 2026. ExfilSquad hackers leak info of over 100,000 UK police officers, staff. BleepingComputer, 3 August 2026.
2. Kundaliya, D. 2026. UK police legal database breach exposes details of more than 100,000 officers and staff. Computing, 4 August 2026.
3. Protos Staff. 2026. 100,000 UK police officers caught in hacker group's ransomware debut. Protos, 3 August 2026.
Back to Blog
Case Studies·3 min read
Why can't the UK's Police National Legal Database explain how 100,000 officer records left the building?
By GoFirm
