News

PNLD Breach: The UK Police Data Leak, the ExfilSquad Campaign, and What Nobody Is Telling You

PNLD breach

On July 26, 2026, a group nobody had heard of before posted to a dark web leak site and claimed they’d breached 15 organisations across five countries, all at once.

Most extortion gangs spend months building a track record. ExfilSquad skipped that part entirely. Two of their claimed victims, the UK’s Department for Education and the Police National Legal Database, have since confirmed breaches. A third, an American city’s non-emergency request portal, was confirmed as publicly accessible to anyone with a browser. A further third, Swedish property developer Bonava, also confirmed an incident. The group’s claim about Microsoft is still unverified.

This is the story of what actually happened, what the data really is, why so many headlines got the numbers wrong, and what the real danger is, especially if you’ve ever typed a question into the “Ask the Police” website.

Quick answer: ExfilSquad, a newly emerged data extortion group, breached the Police National Legal Database (PNLD) — a legal reference service operated by West Yorkshire Police and used by all 43 Home Office police forces, on or before July 26, 2026.

Roughly 135,000 records were published on the dark web, including names, work emails, and force affiliations of around 114,000 law enforcement and criminal justice personnel, plus the contact details of approximately 21,000 members of the public who had used Ask the Police. No passwords, crime records, or victim and witness data were accessed. Researchers believe the breach exploitedNmisconfigured Microsoft Power Pages portals that gave anonymous internet visitors access to data they were never meant to see. no hacking tools required.

What Is the PNLD and Why Does It Matter?

First, a clarification the headlines almost universally skipped. PNLD stands for Police National Legal Database. It is not the Police National Computer, which holds criminal records. It is not the Police National Database, which holds intelligence. It is a legal reference service: think of it as a searchable encyclopedia of policing law and legal guidance, managed by West Yorkshire Police and used across every force in England and Wales.

Officers use it to look up legal powers, case law, and operational guidance, not to record crimes, access informant details, or store anything about victims or witnesses. That’s the PNLD’s own position, confirmed publicly, and investigators have not contradicted it.

The platform also hosts Ask the Police, a public-facing service where members of the public can submit questions about the law and policing. That second category of user is important, and we’ll get to them in a moment.

What Was Taken, and What Wasn’t

ExfilSquad claims to hold 1.9 GB of compressed data: roughly 135,000 records. The North East Regional Organised Crime Unit (NEROCU), which has been supporting the response, confirmed the broader breakdown, approximately 114,000 records belonging to PNLD subscribers (police officers, staff, and criminal justice professionals from partner agencies including the Crown Prosecution Service, Ministry of Defence, National Crime Agency, and others) and around 21,000 records belonging to members of the public who had submitted questions through Ask the Police.

The data that was exposed: names, work email addresses, and police force or organisation affiliations. That’s it, according to PNLD’s official statement. No passwords. No account credentials. No crime records. No victim or witness details. No home addresses. No personal phone numbers.

PNLD has also reported 108,429 police registrations in their 2025-26 annual summary. Tis is a user-base figure, not a breach count, which is part of why the “100,000 police officers” headlines running in some outlets don’t quite add up to the confirmed numbers.

What this means practically: the exposed data is essentially a professional directory. Imagine a LinkedIn export for UK policing. That sounds relatively benign. The problem is what that directory enables, and we’ll come to that shortly.

ExfilSquad: Who Are They and How Did They Do This Without Hacking Anything?

ExfilSquad first appeared on July 26, 2026, the same day as the PNLD listing. Before that date, the group had no known history, no track record, and no prior claims. Their entire public existence began with a leak site naming 15 organisations simultaneously, across five countries, including both private companies and government bodies. Most groups spend months or years building credibility before pulling something this visible.

What makes ExfilSquad genuinely interesting technically is that security researchers found no evidence they used malware, exploit tools, lateral movement, or stolen credentials to access this data. The leading explanation, detailed in analysis published by VenariX and expanded by Fortra, points to misconfigured Microsoft Power Pages portals.

Power Pages is Microsoft’s low-code platform for building public-facing web portals — the kind of online portal a police force might use to run a citizen service like Ask the Police, or a government department might use to run a help desk. Those portals connect to Microsoft Dataverse, the backend database.

Microsoft’s own documentation makes clear that if you assign the “Anonymous Users” web role to a Dataverse table, any data in that table becomes accessible to anyone visiting the site, with no login required. The table permissions also apply to the Web API interface, meaning data could potentially be retrieved in bulk through the portal’s own API layer.

VenariX reviewed data samples associated with 11 of ExfilSquad’s 15 claimed victims. Across all 11, the data structure was consistent with Dataverse exports. In at least one case, the City of Houston’s non-emergency request portal, they confirmed that the portal actively returned records without any authentication, and that those records matched what ExfilSquad had published. Researchers identified more than 10,000 publicly accessible Power Pages instances during their investigation.

Important caveat: PNLD has not confirmed that this is how their breach happened. Their official notice has not identified the access route. The Power Pages link remains an unconfirmed hypothesis for the PNLD incident specifically. But it fits a consistent pattern across the other confirmed victims in the campaign. This kind of misconfigured third-party platform exposure is exactly the sort of attack that bypasses traditional security controls entirely. No firewall to breach, no credentials to steal, just a settings page that nobody checked.

Across the 13 organisations researchers were able to confirm data for in the broader campaign, approximately 27 million records were ultimately published by ExfilSquad.

The DfE Breach: The Other Half of This Story

PNLD wasn’t ExfilSquad’s only confirmed victim in the UK. The Department for Education (DfE) confirmed a separate breach a few days earlier.

The DfE runs services for child protection, education, and apprenticeships across England. ExfilSquad claimed access to two of its portals: the Help Desk Self-Service Portal, used by school staff and local authorities to contact the department, and the Turing Scheme Portal, which handles international study-abroad funding. The group published roughly 607,000 lines of data — names, email addresses, phone numbers, and job titles belonging to headteachers, university administrators, local authority officials, and parents.

DfE clarified that the 607,000 figure represents data lines, not necessarily unique individuals. No financial records, student medical data, or core IT infrastructure was accessed, according to the department. They are working with the Information Commissioner’s Office, the NCSC, and the NCA to investigate.

The Times reported a social engineering element to the DfE attack, a tactic where attackers manipulate staff rather than systems directly. Computer Weekly reported the attackers targeted an internal helpdesk. Details remain limited.

ExfilSquad’s message to both organisations on their leak site was consistent and deliberate: “Once your company’s data is posted here, it’s NEVER leaving the public eye, and it will be passed around the internet FOREVER. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.”

Whether any ransom demand was made to PNLD before the data appeared online has not been confirmed. PNLD said publicly it had not received a demand. Given that the UK government has indicated intent to introduce an effective ban on public sector organisations paying ransoms to cyber criminals, compliance would have been unlikely in any case.

As we’ve covered before in our piece on the AudiA6 takedown, the shift away from pure ransomware toward data extortion is partly a response to exactly this kind of increasing refusal to pay, exfiltrating and publishing data creates pressure without depending on a ransom payment to succeed.

The Real Risk: Targeted Phishing at Scale

PNLD’s official statement is technically accurate in saying the breach is low-risk by some measures. No passwords. No crime data. No home addresses. But it undersells what a consolidated professional directory of 114,000 law enforcement contacts actually enables.

One staff member quoted by Anadolu Agency put it plainly. He worked in serious organised crime, has previously been moved to safe houses, and has had to change his vehicle because of threats related to his work. Seeing his professional details on the dark web wasn’t an abstract concern: “Now I will have to keep my wits about me online and look out for anyone trying to get more serious information.”

The risk isn’t that someone has a serving officer’s work email. The risk is what that email enables. A convincing phishing message addressed to a named officer, referencing their force, their job role, and sent to a confirmed working address, is far more likely to succeed than a generic scam. That officer might be investigating organised crime, running an informant, or working on a sensitive operation. Getting them to click one wrong link, download one bad attachment, or enter credentials into a convincing spoofed site is the opening that a more serious actor needs.

The UK’s National Cyber Security Centre guidance on data breaches, cited in PNLD’s own breach notice, specifically calls this out. Work email addresses being published on the dark web make “phishing messages targeting named officers appear more convincing.” That’s a measured understatement for what this practically enables.

If you’ve worked in serious crime units, counterterrorism policing, or sensitive intelligence roles, your details being on a publicly accessible dark web listing, for anyone to download as a torrent, is genuinely a risk that goes beyond professional inconvenience. And dark web data, as we explain in our monitoring guide, doesn’t disappear once it’s published. It gets mirrored, repackaged, and circulated for years.

The People Nobody Is Talking About: Ask the Police Users

The 21,000 members of the public who submitted questions through Ask the Police are almost absent from most of the coverage on this story, and that’s worth fixing.

Ask the Police is a public service. Regular people, not police officers, not government employees, use it to ask questions like “can my landlord enter my property without notice” or “what should I do if I witness a crime.” They type in their name and email address to get an answer. They almost certainly didn’t expect that information to end up in a 1.9 GB torrent file on a dark web extortion group’s site.

Those 21,000 people have no professional training in spotting phishing. They didn’t choose to engage with a sensitive law enforcement database.

They asked a legal question on a government-facing website. PNLD has confirmed they emailed those affected users directly. But the data is already out there, and if any of those individuals used the same email address for banking, shopping, or social media accounts, they’re now at slightly elevated phishing risk.

This is exactly the gap that dark web monitoring exists to close. Finding out your data is circulating before someone uses it to target you, rather than after.

What’s Still Unknown

As of early September 2026, several important questions remain unanswered:

The confirmed access route for the PNLD specifically has not been disclosed. PNLD hasn’t confirmed whether the Power Pages hypothesis applies to their incident. West Yorkshire Police, which operates PNLD, hasn’t responded publicly to detailed technical questions.

The total number of unique individuals affected hasn’t been confirmed. The 135,000 figure comes from ExfilSquad’s own claim, supported by NEROCU’s breakdown of 114,000 professional records and 21,000 public contacts. PNLD has not confirmed those numbers officially.

Whether ExfilSquad made a ransom demand before publishing is unconfirmed by PNLD. ExfilSquad’s posting behaviour across other victims suggests demands were made, but PNLD’s statement says no demand was received, which could mean the group went straight to publishing, or that communications happened through a channel not yet disclosed.

What Organisations Using Microsoft Power Pages Should Do Right Now

If your organisation runs a Power Pages portal, this campaign is a direct warning regardless of whether you were in ExfilSquad’s claimed list.

VenariX’s recommendation is straightforward. Review which Dataverse tables are assigned to the Anonymous Users web role. Check whether the Web API or legacy OData feed is enabled, and whether it returns records to unauthenticated requests. Then open an incognito browser window and attempt to browse your own portal as an anonymous visitor. What you can see is what anyone on the internet can see.

Microsoft’s own documentation provides a tenant-level governance setting that blocks unauthenticated users from reading , Dataverse data while still allowing public form submissionsthe kind of interaction a citizen-facing portal genuinely needs.

The uncomfortable lesson of this campaign is that 27 million records across at least 13 organisations were reportedly accessed without a single line of exploit code. No zero-day. No credential stuffing. No malware. Just permissions settings that were too broad, sitting on portals that anyone with an internet connection could reach.

Keeping attackers out is necessary. Limiting what they can reach when they inevitably get in, or when no “getting in” is required at all, is the part that organisations keep skipping.

Freuently Asked Quetions

What is the PNLD breach?

The Police National Legal Database, a legal reference service managed by West Yorkshire Police for all 43 Home Office police forces, had approximately 135,000 contact records published on the dark web on July 26, 2026. The data includes names, work emails, and force affiliations of law enforcement and criminal justice professionals, and contact details of around 21,000 public users of the Ask the Police service.

Who is ExfilSquad?

A data extortion group that first appeared publicly on July 26, 2026, simultaneously claiming 15 victims across five countries. Two UK government institutions (PNLD and the Department for Education) have confirmed breaches. No malware or traditional hacking is believed to have been used.

How did ExfilSquad access the data?

Researchers from VenariX and Fortra believe the group exploited misconfigured Microsoft Power Pages portals that granted the Anonymous Users web role overly broad access to Microsoft Dataverse tables, making the data available to anyone visiting the site without authentication. This has not been confirmed as the specific cause in the PNLD incident.

Was sensitive police data exposed, crime records, informant details?

No. PNLD does not hold crime records, victim details, witness information, or investigative data. What was exposed was effectively a professional contact directory: names, work emails, and force affiliations.

What should I do if I’ve used Ask the Police?

You should have received an email from PNLD if your details were affected. Stay alert to phishing emails that reference your real name. Don’t click links in unsolicited messages.  Go directly to official websites instead. If you’re concerned your email address is circulating on the dark web, a monitoring service can alert you to new exposures.

Was a ransom paid?

PNLD has stated it received no ransom demand in connection with the incident. Given the UK government’s stated direction toward banning public sector ransom payments, payment would be highly unlikely in any case.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted