UK Police Database Data Breach Exposed in Security Alert

▼ Summary
– A database containing work details of British police officers and criminal justice professionals was compromised, with names, organizations, and work email addresses published on the dark web.
– The Police National Legal Database (PNLD), managed by West Yorkshire Police, covers all 43 police forces in England and Wales, plus agencies like the Crown Prosecution Service and British Transport Police.
– The data security incident was identified on July 26, with no evidence that passwords or other security credentials were compromised.
– The Ask the Police service was also affected, leaking names and email addresses of people who submitted questions, though no confidential victim, witness, or offender data is held.
– The extortion group ExfilSquad claimed responsibility, stating it had 1.9GB of data and 135,000 records, but payment is unlikely due to a UK government ban on public sector extortion payments.
A security alert has revealed that a critical database holding employment details for UK police officers and criminal justice personnel has been breached. The incident raises serious concerns about targeted cyberattacks against those tasked with upholding the law.
The Police National Legal Database (PNLD), which is operated under the management of West Yorkshire Police, serves as a central repository for workforce information. Its reach extends to all 43 police forces across England and Wales, alongside the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct, and His Majesty’s Courts and Tribunals Service.
In a public notice released on August 3, the PNLD confirmed it had identified a “data security incident” on July 26. The statement detailed that sensitive professional information had been exfiltrated and subsequently leaked online.
“Information including the names, organizations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web. There is no evidence to suggest that passwords or other security credentials have been compromised,” the notice read.
The organization stated that it has since enlisted the help of specialist cybersecurity firms and the National Crime Agency to investigate the breach and mitigate further risks.
The fallout extends beyond internal staff records. The PNLD’s public-facing Ask the Police service was also caught up in the incident. The notice warned that individuals who had previously submitted queries through this platform may have had their personal details exposed.
“As a result, some names and email addresses of people who have previously submitted a question to Ask the Police have been published on the dark web,” the notice added. “If you have been affected, you will have already received an email from Ask the Police with more information and guidance.”
Officials were quick to clarify that the compromised database did not contain sensitive case files, victim statements, or offender records, limiting the scope of the data loss to professional contact details.
ExfilSquad Claims Responsibility for PNLD Hack
The breach has been attributed to ExfilSquad, a cyber extortion group already known for a recent attack on the UK’s Department for Education. The group has posted claims on its leak site, asserting it possesses a cache of 1.9GB of data, which includes roughly 135,000 records. A portion of this data has reportedly been published to demonstrate the severity of the threat.
In a message typical of extortion tactics, the group stated: “Once your company’s data is posted here it’s never leaving the public eye and will be passed around the internet forever. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.”
Despite the pressure, it is highly improbable that the PNLD will comply with the ransom. The UK government has signaled its intent to implement a de facto ban on public sector bodies paying ransoms to cybercriminals, a policy designed to starve these groups of funding.
For the officers and staff whose details are now in the public domain, the immediate risk lies in follow-on attacks. The leaked information provides cybercriminals with a verified directory of targets, enabling highly convincing phishing campaigns.
Dray Agha, senior manager of the security operations center EMEA at Huntress, underscored the gravity of the situation. “While the absence of compromised passwords is a relief, exposing the names and work emails of UK police and justice staff on the dark web hands cybercriminals a readymade directory to launch highly targeted spear-phishing and social engineering attacks against the very people defending our justice system.”
(Source: Infosecurity Magazine)


