The Police National Legal Database (PNLD) has confirmed a data breach that exposed contact details of U.K. police officers, government partners, and customers on the dark web. The compromised data includes names, organizations, and work email addresses of police staff, criminal justice professionals, and individuals who submitted questions via the Ask the Police service. The breach was identified on July 26, 2026, and PNLD stated there is no evidence that passwords or other security credentials were compromised.
PNLD provides legal information and services to U.K. police forces and criminal justice organizations. It is not the Police National Computer or the Police National Database, and it does not hold confidential information about victims, witnesses, or offenders. The organization has contacted affected parties, notified the Information Commissioner’s Office (ICO), and is working with the National Crime Agency (NCA) and specialist cybersecurity firms. As of August 3, 2026, PNLD has not disclosed the number of affected individuals, the attack vector, or the full extent of the data exfiltration.
Security researchers at VenariX analyzed samples from 11 of the 15 claimed victims of the threat actor ExfilSquad, which listed PNLD on its leak site. VenariX found Dataverse-consistent structures across all samples and assessed that the likely attack path involved a public Power Pages site with broad Anonymous Users access to Dataverse tables, possibly via an enabled Web API or legacy OData feed. However, VenariX noted that the evidence does not confirm every organization was affected through the same configuration issue, and no PNLD-specific endpoint or permission setting has been identified. Microsoft provides tenant-level governance controls to block unauthenticated access to Dataverse data, and VenariX recommends Power Pages operators review Anonymous Users permissions and API settings.
PNLD has not attributed the breach to ExfilSquad, and VenariX found no evidence of ransomware, malware, or exploitation of a software vulnerability. The investigation is ongoing, and further details are expected as authorities continue their work.
CVEs: CVE-2026-50522
Attack groups: ExfilSquad
Products: Power Pages, Dataverse
Original source: thehackernews.com