A major cyberattack has exposed the personal details of more than 100,000 police officers, staff members, and criminal justice professionals across the United Kingdom. The attack targeted the Police National Legal Database (PNLD), an online legal resource used by police forces in England and Wales. Officials confirmed that the breach affected contact information stored within the system.

According to PNLD, the exposed information includes full names, work email addresses, and the organizations where the affected individuals work. Some records linked to members of the public who used the “Ask the Police” service were also impacted. Authorities have not reported that passwords, financial details, or classified investigation files were part of the leaked data.
The attack was claimed by a cybercrime group known as ExfilSquad, which says it stole around 135,000 contact records from the database. The group published samples of the stolen information on its dark web leak site after claiming responsibility for the intrusion. Investigators are still examining the full scale of the incident and verifying all of the hackers’ claims.

The Police National Legal Database has been used for more than three decades by all 43 Home Office police forces in England and Wales, along with the British Transport Police. It provides officers with legal guidance and policing information needed during daily operations. Because of its widespread use, the breach has raised serious concerns across UK law enforcement.
Reports also indicate that the same cyber campaign affected several other UK government organizations, including the Ministry of Defence, the Home Office, the National Crime Agency, and the Crown Prosecution Service. The incident follows another recent breach involving the UK’s Department for Education, suggesting that multiple public sector organizations have recently been targeted.

Cybersecurity experts have warned that even basic contact information can be highly valuable to attackers. Criminals may use the leaked names, email addresses, and organizational details to launch convincing phishing campaigns or social engineering attacks against police officers and government employees. This could increase the risk of further security incidents if the information is abused.
UK authorities have launched investigations into the breach, with organizations working alongside cybersecurity specialists to understand how the attackers gained access and to reduce any further risks. The Information Commissioner’s Office has also been informed, while the National Cyber Security Centre and law enforcement agencies continue to support the response. Officials have stated that the investigation is still ongoing.

The incident highlights the growing cybersecurity challenges facing government organizations as threat groups continue targeting public sector systems. Protecting employee information has become increasingly important because even limited personal data can be exploited for future attacks. The ExfilSquad breach serves as another reminder that strong cybersecurity measures and continuous monitoring remain essential for protecting critical public services.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news