
UK Police Data Breach Exposes Contact Details of 100,000 Officers
.webp)
Attackers have exposed the contact details of more than 100,000 police officers and criminal justice professionals across England and Wales. The police data breach hit the UK Police National Legal Database, an online legal reference service that has supported forces for over three decades. Staff detected the intrusion on Sunday, 26 July 2026. A data extortion group calling itself ExfilSquad later claimed the attack and began demanding payment.
The stolen material contains no case files, no witness statements, and no offender records. Instead, the UK police data breach handed criminals a clean list of names, employers, and email addresses. That sounds modest until you consider who those names belong to.
What the UK Police Data Breach Exposed
The Police National Legal Database, known as PNLD, serves all 43 Home Office forces in England and Wales alongside the British Transport Police. Officers use it to check points of law, powers of arrest, and charging guidance during live work. It also runs Ask the Police, a public site that answers common legal questions from members of the public. Both user groups appear in the data exposed by the UK police breach.
PNLD says the data breach revealed full names, organisations, and email addresses. Those records belong to serving officers, police staff, criminal justice professionals, and government partners. Names and email addresses of Ask the Police users who submitted a question also sit in the stolen set.
Investigators have found no evidence that passwords or other security credentials left the system. The service holds no confidential information about victims, witnesses, or offenders, so the UK police data breach never touched operational case material. PNLD has not explained how theat tackers got in, and it has not publicly named a culprit.
ExfilSquad Claims 135,000 Stolen Records
The group behind the UK police data breach published sample records to support its claim. ExfilSquad alleges it took 1.9 GB of material covering roughly 135,000 records. It splits that figure into about 114,000 PNLD subscribers and around 21,000 Ask the Police users. None of those numbers carry independent verification.
The group also demanded a ransom in exchange for withholding the remaining files. PNLD has confirmed both the intrusion and the publication of contact details. It has said nothing about how it intends to answer the extortion demand, and no deadline or payment figure has surfaced publicly.
ExfilSquad claimed a separate attack on American semiconductor firm Analog Devices days earlier. That listing alleged roughly 570,000 records containing customer personal information and home addresses. Across both incidents, the group leans on data theft and public pressure rather than file encryption.
Why Contact Data Carries Outsized Risk for Officers
Corporate email lists leak constantly, and most cause limited damage. A verified roster of law enforcement personnel behaves very differently. Attackers gain a confirmed picture of who works where, which turns scattergun phishing into credible, targeted approaches.
Anyone holding these records can write messages that reference the right force, the right role, and the right internal service.Officers already expect legitimate mail from PNLD about legal updates. Criminals can now imitate exactly that traffic. Credential theft and malware delivery both get easier.
A doxxing risk runs alongside it. Analysts and criminals alike cross-reference names and emails against older breach documentation, social media, and public records. That process can surface home addresses and family details, which matters far more for a serving officer than for an average office worker. The UK police data breach therefore raises a personal safety question as much as an information security one.
A New Extortion Brand With Unverified Claims
ExfilSquad surfaced publicly in late July 2026 with a Tor leak site already carrying claims against around 15 organisations. Within a single week it logged 14 victim listings. Those targets span the United States, the United Kingdom, and Nigeria, covering technology, finance, government, education, and law enforcement.
That volume invites scepticism. Researchers tracking the group describe an exfiltration-only model with no confirmed encryption activity. Several listings lack samples, file trees, or any other proof of access. One claim against Microsoft alleged eight million records and arrived with nothing to substantiate it.
Some aggregator sites date the operation to late 2024, but detailed threat intelligence work has found no reliably linked earlier activity. Treat the group as new and treat its figures as claims. Unlike most of its listings, the UK police data breach involves a victim that has confirmed a genuine intrusion.
Response, Regulators, and What Comes Next
PNLD is working with external cybersecurity specialists and the National Crime Agency. It notified the Information Commissioner's Office and contacted affected organisations within days of detection. Those bodies received guidance on what the exposure covers and how to respond.
Forces now face a straightforward operational task. Every officer and staff member on that list needs a warning about targeted phishing, and every inbound message referencing legal guidance deserves fresh scrutiny. Nobody can rotate an email address as easily as a password, so the elevated risk here persists for years rather than weeks.
Extortion crews are testing which datasets generate real pressure, and the UK police data breach gives them an answer. Contact information for law enforcement carries obvious leverage, and this incident proves the point without a single stolen password. Any organisation sitting on a directory of sensitive professionals should read the case closely, because attackers clearly value that material even when it looks unremarkable on paper.
Subscribe to receive the latest blog posts to your inbox every week.