The Police National Legal Database (PNLD) has confirmed that contact information belonging to police officers, government personnel, and users of the Ask the Police service was compromised and published on the dark web on July 26, 2026. The official notification, made public in early August, outlines an incident striking at the operational heart of UK law enforcement without providing the full picture: neither the technical vector, the exact victim count, nor the intrusion duration have been disclosed.
Attribution to the ExfilSquad group, active on cybercrime forums, has not been confirmed by the PNLD. Meanwhile, a technical hypothesis advanced by security firm VenariX regarding a potential attack chain through misconfigured Microsoft Power Pages portals remains unverified for this specific case.
- The PNLD confirmed the exposure of names, organizations, and work email addresses of police officers, criminal justice professionals, government partners, and Ask the Police service users.
- The incident was identified on July 26, 2026; ExfilSquad listed the PNLD on its leak site the same day, but the organization has not confirmed the attribution.
- VenariX found patterns consistent with Microsoft Dataverse tables in 11 of 15 victims claimed by ExfilSquad, but identified no specific endpoints, permissions, or logs for the PNLD.
- An unresolved conflict exists between the PNLD's official statement, which rules out password compromise, and a Guardian reconstruction based on internal sources.
What We Know From the Official Notification
The PNLD stated that exposed data includes names, organizations, and work email addresses of police, staff, criminal justice professionals, government partners, and customers. Also involved were the names of individuals who had submitted queries through the Ask the Police portal, a public information service managed by the organization.
In its statement, the PNLD firmly defined the incident's boundaries: "There is no evidence that passwords or other security credentials have been compromised." The organization also clarified that it is not the Police National Computer nor the Police National Database, does not constitute a crime recording system, and does not hold confidential information on victims, witnesses, or offenders.
On the procedural front, the PNLD contacted all affected organizations, notified the Information Commissioner's Office (ICO), and is collaborating with the National Crime Agency (NCA) and specialized cybersecurity organizations. As of August 3, 2026, however, the PNLD had not publicly disclosed the number of affected individuals, the intrusion start date, its duration, or the volume of data taken.
The Power Pages Hypothesis and the Limits of the VenariX Analysis
The most detailed technical reconstruction comes from VenariX, which examined samples associated with 11 of the 15 victims claimed by ExfilSquad. In all 11 cases, the firm found structures consistent with Microsoft Dataverse tables, the database underlying Microsoft's Power Platform. In the specific case of the City of Houston, VenariX confirmed that a public portal returned records without authentication and that those records were consistent with the data published by the criminal group.
From this evidence, VenariX drew a campaign assessment: the likely path runs through public Power Pages sites with excessive permissions for the Anonymous Users role on Dataverse tables, with Web API or legacy OData feeds enabled. This configuration allows data extraction without authentication.
However, the analysis contains an explicit and binding caveat. VenariX stated the evidence "does not yet confirm that every organization was hit through an exposed Power Apps portal or the same misconfiguration issue." As of August 3, 2026, neither the PNLD notification nor the VenariX report had identified a specific endpoint, permission setting, API route, or supporting log for the UK organization. The Hacker News summarized the picture clearly: "the Power Pages link remains a hypothesis to be tested rather than a confirmed explanation of the PNLD breach."
Additional context emerges from PNLD's institutional communications: in its 2023-24 annual summary, the organization stated its database uses Microsoft Power Platform technology. The Hacker News also confirmed that the breach notice page referenced assets hosted on Microsoft's content.powerapps.com domain. These elements make the technical hypothesis plausible without elevating it to certainty.
The 135,000 Data Items Figure and the Password Conflict
The Guardian provided the most specific quantitative figure among available sources, reporting that cybercriminals claimed 135,000 data items from the PNLD. This figure finds no confirmation in the organization's official notification or in analyses from other primary sources. Sophos, cited by The Guardian, provided leak site screenshots and assessed that the data samples appeared legitimate.
The Guardian further reported, citing a senior source briefed on the leak, that the PNLD breach includes the theft of passwords used to access the site. This assertion directly contradicts the PNLD's official statement, which explicitly denies the compromise of security credentials. The same senior source downplayed the immediate risk: "The risk is low. The question is, if you use your password for PNLD, do you use it for more sensitive systems?"
The dossier does not allow resolution of this conflict. The discrepancy between the journalistic reconstruction based on internal sources and the official institutional communication remains one of the main limitations of the available documentation.
Why It Matters
The dossier does not specify technical remedial measures adopted by the PNLD after the incident. It does not document whether the organization modified access configurations for its Power Platform assets, revoked active sessions, or initiated an audit of Anonymous Users permissions. The brief does not report mitigating interventions indicated by the source.
The dossier does not list additional technical entities such as secrets, SSH keys, source code, host filesystems, tokens, API keys, or certificates as objects of compromise. It does not document whether other UK government organizations using Power Pages were involved in similar incidents in the same timeframe.
The dossier does not specify whether Microsoft released communications or security updates in response to the VenariX hypotheses. It also does not document whether the tenant-level governance control described by VenariX — which blocks unauthenticated users from reading Dataverse data while allowing public form submissions — has been the subject of a formal recommendation to platform users.
"The reviewed data is most consistent with extraction from public Microsoft Power Pages portals that were configured to allow anonymous users to read Dataverse records." — VenariX
Implications of the ExfilSquad Campaign for Government Security
The ExfilSquad campaign, in VenariX's reconstruction, stands out for a specific operational pattern: no ransomware deployment, no malware use, no lateral movement, and no software vulnerability exploitation in the examined material. The group limits itself to data exfiltration from public portals, then monetizes through leak site publication and payment demands. On its sales site, ExfilSquad framed its offer pragmatically: "The payment we require is simply a rounding error compared to the litigation costs from your data leak. Be smart and pay."
This modus operandi has far-reaching implications for organizations using low-code and no-code platforms to publish public services. The ease with which a Power Pages portal can be configured to allow excessive anonymous access — combined with the public visibility of the infrastructure — creates an attack surface requiring no technical sophistication from the attacker. Verification of access configurations becomes a critical governance control, not an implementation detail.
For UK law enforcement and criminal justice personnel, the exposure of work email addresses on the dark web increases the risk of targeted spear phishing. An attacker who knows an officer's name, organization, and institutional address has sufficient elements to craft highly personalized social engineering messages, with potential impact on operational security.
The PNLD case fits into a broader context of fragility in government technology supply chains based on public cloud. Adoption of platforms like Microsoft Power Platform for public service digitalization brings deployment speed advantages but transfers responsibility for secure configuration — which the vendor does not guarantee by default — to the consuming organization. The distinction between legitimate public forms and excessive anonymous access to data tables requires specific competencies not always distributed across public administration IT departments.
The gap between the technical hypothesis advanced by a security vendor and the lack of official confirmation from the breached organization raises a post-incident communication issue. When the root cause is undetermined, public narrative management becomes a precarious balance between transparency and the risk of providing incorrect information. The PNLD opted for communication confined to established facts, declining to hypothesize about the vector; other organizations in similar situations have preferred to indicate investigative paths even if inconclusive. No standard protocol exists, and the case highlights how the lack of a shared framework can leave room for parallel reconstructions, not always aligned.
Information has been verified against cited sources and updated at time of publication.
Information has been verified against cited sources and updated at time of publication.
Sources
- https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
- https://thomasharris6.wordpress.com/2026/08/03/pnld-breach-exposes-u-k-police-and-government-contact-details-on-dark-web/
- https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html
- https://www.reconbee.com/pnld-breach-exposes-u-k-police-and-government-contact-details-on-dark-web/
- https://www.theguardian.com/technology/2026/jul/29/department-for-education-police-hackers-cybercrime
- https://support.theguardian.com/us/contribute?REFPVID=mse2omy4yuus7myxgvne&INTCMP=header_support_2025-07-23_JULY_DISCOUNT_HEADER__UK_EU_ROW_US_AUS_CONTROL&acquisitionData=%7B%22source%22%3A%22GUARDIAN_WEB%22%2C%22componentId%22%3A%22header_support_2025-07-23_JULY_DISCOUNT_HEADER__UK_EU_ROW_US_AUS_CONTROL%22%2C%22componentType%22%3A%22ACQUISITIONS_HEADER%22%2C%22campaignCode%22%3A%22header_support_2025-07-23_JULY_DISCOUNT_HEADER__UK_EU_ROW_US_AUS_CONTROL%22%2C%22abTests%22%3A%5B%7B%22name%22%3A%222025-07-23_JULY_DISCOUNT_HEADER__UK_EU_ROW_US_AUS%22%2C%22variant%22%3A%22CONTROL%22%7D%5D%2C%22referrerPageviewId%22%3A%22mse2omy4yuus7myxgvne%22%2C%22referrerUrl%22%3A%22https%3A%2F%2Fwww.theguardian.com%2Ftechnology%2F2026%2Fjul%2F29%2Fdepartment-for-education-police-hackers-cybercrime%22%2C%22isRemote%22%3Atrue%7D
- https://support.theguardian.com/subscribe/weekly?REFPVID=mse2omy4yuus7myxgvne&INTCMP=undefined&acquisitionData=%7B%22source%22%3A%22GUARDIAN_WEB%22%2C%22componentId%22%3A%22PrintSubscriptionsHeaderLink%22%2C%22componentType%22%3A%22ACQUISITIONS_HEADER%22%2C%22referrerPageviewId%22%3A%22mse2omy4yuus7myxgvne%22%2C%22referrerUrl%22%3A%22https%3A%2F%2Fwww.theguardian.com%2Ftechnology%2F2026%2Fjul%2F29%2Fdepartment-for-education-police-hackers-cybercrime%22%7D
- https://support.theguardian.com/?INTCMP=side_menu_support&acquisitionData=%7B%22source%22:%22GUARDIAN_WEB%22,%22componentType%22:%22ACQUISITIONS_HEADER%22,%22componentId%22:%22side_menu_support%22%7D
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html