PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

3 hours ago 2

Swati KhandelwalAug 03, 2026Data Breach / Dark Web

The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.

The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.

The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police. That exposure could make phishing messages targeting named officers appear more convincing, according to UK government guidance.

PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The service provides legal information, products and services to UK police forces and criminal justice organisations. It is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not hold confidential information about victims, witnesses or offenders.

PNLD says it contacted all affected organisations and provided them with further information and guidance. Affected Ask the Police users have already received an email with more information and guidance. It notified the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organisations.

Cybersecurity

As of August 3, 2026, it had not publicly disclosed how many people were affected, when the intrusion began, how long access lasted, or how much information was taken.

PNLD's official breach notice describes the exposed fields but provides no victim total. PNLD reported 108,429 police registrations and support for all 43 Home Office police forces in its 2025-26 annual summary. That is a user-base figure, not a breach-victim count.

PNLD said in its 2023-24 annual summary that the database uses Microsoft Power Platform technology. The Hacker News confirmed on August 3, 2026, that the breach-notice page referenced assets hosted on Microsoft's content.powerapps.com domain. That corroborates the platform connection but does not show how the attacker obtained the data.

VenariX reviewed samples associated with 11 of ExfilSquad's 15 claimed victims and found Dataverse-consistent structures across all 11. In the Houston case, it confirmed that a public portal returned records without authentication and that those records were consistent with data published by the group.

VenariX assessed the likely campaign-level path as a public Power Pages site with broad Anonymous Users access to Dataverse tables. The path also required an enabled Power Pages Web API or legacy OData feed.

Microsoft's documentation says granting the Anonymous Users role access to a table makes its data visible to anyone visiting the site. Its Web API documentation says the /_api interface follows the table permissions attached to each web role.

VenariX said the evidence "does not yet confirm that every organization was affected through an exposed Power Apps portal or the same configuration issue." As of August 3, 2026, neither PNLD's notice nor VenariX's report identified a PNLD-specific endpoint, permission setting, API route, or supporting log.

Cybersecurity

At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach.

Microsoft provides a tenant-level governance control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions.

VenariX recommends that Power Pages operators also review Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validate access from an unauthenticated browser session. Those measures address the configuration pattern identified by VenariX, not a confirmed PNLD root cause.

ExfilSquad listed PNLD on its leak site on July 26, but PNLD has not attributed the incident to the group. VenariX found no evidence of ransomware deployment, malware use, lateral movement or exploitation of a software vulnerability in the campaign material it examined.

PNLD has not publicly disclosed the exact access route, the number of unique people affected or the full volume of data published.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article