ExfilSquad breaches UK police data for 100K+ officers, staff

▼ Summary
– A cyberattack on the U.K.’s Police National Legal Database (PNLD) compromised contact data of over 100,000 police officers and criminal justice professionals.
– The intrusion was detected on July 26 and claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records.
– The breach exposed full names, organizations, and email addresses of police staff, criminal justice professionals, and Ask the Police users who submitted questions.
– The incident is under investigation with cybersecurity experts and the National Crime Agency; no passwords or security credentials were compromised, and no data on victims, witnesses, or offenders was impacted.
– ExfilSquad demanded a ransom to prevent release of the stolen data, claiming 1.9 GB including records from 114,000 PNLD subscribers and 21,000 Ask the Police users.
A cyber intrusion targeting the U.K.’s Police National Legal Database (PNLD) has exposed the contact details of more than 100,000 police officers and allied criminal justice personnel.
The breach was detected on Sunday, July 26, and has since been claimed by the ExfilSquad data extortion group, which asserts it exfiltrated 135,000 contact records. PNLD serves as an online legal reference tool, relied upon for over three decades by the 43 Home Office police forces across England and Wales, in addition to the British Transport Police. The service also powers “Ask the Police,” a public-facing portal that fields hundreds of routine policing and legal inquiries.
According to a statement released today, the compromised information includes full names, organizational affiliations, and email addresses of police officers, support staff, criminal justice professionals, and government partners. The names and email addresses of individuals who submitted questions via the Ask the Police platform are also considered exposed.
An investigation is now underway, supported by cybersecurity specialists and the National Crime Agency (NCA). To date, there is no evidence indicating that passwords or other security credentials were accessed. PNLD has clarified that it does not store confidential information pertaining to victims, witnesses, or offenders, and confirms that no such data was affected.
“All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner’s Office (ICO) has also been notified,” PNLD stated.
The ExfilSquad group has taken credit for the PNLD breach, releasing sample data as proof and demanding a ransom to prevent the disclosure of the remaining stolen information. The threat actor claims to have extracted 1.9 GB of data, containing roughly 135,000 records, including details for 114,000 PNLD subscribers and 21,000 Ask the Police users.
ExfilSquad is the same collective recently linked to an attack on Analog Devices, the American semiconductor manufacturer. While PNLD has confirmed the breach and the publication of contact details, it has refrained from publicly identifying the attackers or detailing the method of unauthorized access. BleepingComputer has reached out to PNLD for additional insights and will provide updates as new information emerges.
(Source: BleepingComputer)




