The personal details of approximately 100,000 UK police officers and staff have been leaked on the dark web following a sophisticated cyberattack on the Police National Legal Database (PNLD). The breach, which surfaced late Sunday, has caused significant alarm among law enforcement personnel, many of whom have spent their careers investigating the very criminals now potentially in possession of their information. The PNLD is an online resource used by police forces across the UK to access legal guidance, and the stolen data includes names, force affiliations, and work email addresses.
This incident is part of a broader wave of cyberattacks targeting UK public institutions. The same hacking group, identified as ExfilSquad, is also believed to be responsible for a separate, larger breach at the Department for Education (DfE) that compromised over 600,000 records. Together, these attacks have exposed more than 740,000 pieces of data, including contact information for government officials, school leaders, and members of the public who have interacted with police services.
While authorities have stated that the PNLD database did not contain sensitive information such as victim, witness, or offender records, the exposure of police identities remains a serious concern. For officers working in sensitive roles, such as those in serious organized crime units, the leak presents a tangible risk to their safety and privacy. Some affected staff have already expressed fears about the potential for targeted harassment or the need to alter their living arrangements to ensure their security.
ExfilSquad has reportedly demanded payment in exchange for withholding the remainder of the stolen data, a common tactic used by cybercriminal groups to monetize their activities. The National Crime Agency and other security bodies are currently investigating the breaches. As the situation develops, affected police forces are working to provide guidance to their staff, while the government faces mounting pressure to explain how such a significant volume of sensitive data was left vulnerable to external threat actors.