UK Police National Legal Database breach exposes 100,000 officers' data
A cyberattack on the Police National Legal Database (PNLD) has leaked the contact details of more than 100,000 police officers, staff and criminal‑justice professionals across all 43 police forces in England and Wales. The breach, discovered on 26 July 2026, exposed names, employing organisations and work email addresses but no passwords or other security credentials. The data, which also included information on employees of the Ministry of Defence, Home Office, National Crime Agency and Crown Prosecution Service, appeared on the dark web. The hacker group ExfilSquad has claimed responsibility and demanded payment to remove the data. The PNLD has notified the Information Commissioner’s Office and is working with the National Crime Agency and specialist cyber‑security firms, while police officials warn of heightened risk of social‑engineering attacks.
Police Federation chair Tiff Lynch said the leak raises serious concerns for officer safety and called for stronger cyber‑security funding. A government spokesperson confirmed dedicated capabilities to respond to the incident but declined further comment.
Entities: Denis Calderone · ExfilSquad · Information Commissioner’s Office · National Crime Agency · Police National Legal Database · Police National Legal Database (PNLD) · Seemant Sehgal · Tiff Lynch · UK Home Office police forces
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] The compromised information includes names, employing organisations and work email addresses of police officers, staff and criminal‑justice professionals. (All articles)
- [● 3 SOURCES] The hacker group ExfilSquad claimed responsibility for the breach. (Articles 95ec0573, 2e4f300a, 9cec31b4)
- [● 4 SOURCES] The breach affected staff from all 43 police forces in England and Wales. (All articles)
- [● 4 SOURCES] More than 100,000 police officers and staff contact details were leaked on the dark web. (All articles)
- [● 2 SOURCES] The Information Commissioner’s Office was notified about the breach. (Articles 95ec0573, 8113335a)
- [● 2 SOURCES] The breach was discovered on 26 July 2026. (Articles 2e4f300a, 8113335a)
- [● 3 SOURCES] No passwords or other security credentials were compromised in the breach. (Articles 95ec0573, 9cec31b4, 8113335a)
- [● 2 SOURCES] The leak also exposed data of Ministry of Defence, Home Office, National Crime Agency and Crown Prosecution Service employees. (Articles 95ec0573, 9cec31b4)