// 2 CRITICAL · 4 ZERO-DAY · 6 CVE · 6 EXPLOIT IN THE LAST 24H
The emerging ransomware group ExfilSquad has exfiltrated contact data for over 100,000 officers from the UK Police National Legal Database. The technical pattern reveals pure data extortion without encryption, likely exploiting misconfigured Microsoft Power Pages portals rather than software vulnerabilities.

On July 26, 2026, the UK Police National Legal Database (PNLD) confirmed a personal data compromise that exposed names, email addresses, and institutional affiliations of more than 100,000 police officers and justice-sector personnel. The emerging ransomware group ExfilSquad claimed responsibility, marking its debut with a data extortion campaign that deployed no encryption on target systems. The ransom payment deadline was set for August 5.

Key Takeaways
  • ExfilSquad exfiltrated contact data for over 100,000 officers and justice personnel from the UK PNLD, including 2,615 Crown Prosecution Service employees, 617 Home Office staff, 588 National Crime Agency personnel, and 402 Ministry of Defence staff.
  • The PNLD confirmed the compromise but ruled out involvement of passwords or security credentials; the database does not contain data on victims, witnesses, or offenders.
  • VenariX analysis of 11 victim samples found Dataverse-consistent structures and no evidence of ransomware deployment, malware, or software vulnerability exploitation.
  • The probable attack path runs through public Microsoft Power Pages portals with Anonymous Users access and Web API enabled, rather than code flaws.

The Method: Pure Extortion Without Encryption

ExfilSquad operates a model that diverges from traditional ransomware. According to VenariX analysis of campaign materials from 11 victims, the group deployed no ransomware, performed no lateral movement, and exploited no software vulnerabilities. The tactic is pure data extortion: exfiltration of sensitive data and threat of publication to extort payment.

The message posted on the group's leak site is explicit about the economic logic: "Once your company's data is posted here, it's NEVER leaving the public eye and it will be passed around the internet FOREVER. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay."

This approach eliminates the need for complex exploit development or network pivoting skills, lowering the barrier to entry for actors who instead rely on cloud configuration and low-code platform knowledge.

The Technical Vector: Low-Code Platforms, Not Zero-Day Vulnerabilities

The PNLD uses Microsoft Power Platform technology. The organization's breach notice referenced assets hosted on content.powerapps.com. VenariX examined this evidence and identified Dataverse-consistent structures—the platform's underlying database—in 11 samples.

In one case, a public portal without authentication was confirmed. The analysts' hypothesized path involves a Power Pages site exposed with Anonymous Users permissions to Dataverse tables, with Web API or OData feeds enabled. This configuration allows access to structured data without the actor needing to bypass identity controls.

However, VenariX explicitly limited the scope of its analysis: "does not yet confirm that every organization was affected through an exposed Power Apps portal or the same configuration issue." The specific root cause of the PNLD breach remains unconfirmed. The PNLD itself has not publicly attributed the incident to ExfilSquad nor disclosed the access vector.

The Breach Numbers: Over 100,000, With Nuance

"more than 100,000" — BleepingComputer on the PNLD compromise; The Times confirmed the legitimacy of ExfilSquad's dark web list

The exposed data, according to Protos and The Times, includes full names, email addresses, and workplace details of PNLD personnel. ExfilSquad's list also reported 2,615 Crown Prosecution Service (CPS) employees, 617 Home Office staff, 588 National Crime Agency (NCA) personnel, and 402 Ministry of Defence (MoD) staff.

ExfilSquad claimed 135,000 law enforcement records, but researchers have questioned the validity of this figure. The PNLD reported 108,429 police registrations in fiscal year 2025-26, but this figure represents the platform's total user base, not the breach victim count. The exact number of unique individuals compromised has not been officially disclosed.

The group has claimed 15 companies and government agencies in total, including Microsoft and the UK Department for Education, signaling aggressive targeting of high-profile institutional and commercial targets.

Why It Matters

The ExfilSquad-PNLD case highlights a specific public-sector risk pattern: legacy infrastructure and fragmented cloud security expertise. Low-code platforms like Microsoft Power Platform accelerate development but expand the attack surface through configurations that do not always undergo security review equivalent to traditional code.

For British law enforcement, the exposure of contact data creates concrete risks of targeted spear-phishing and personal targeting of operational agents. The Times reported the hack "appears financially rather than politically motivated," but the distinction offers little comfort when the data remains permanently in circulation.

The political context adds urgency: the UK government is planning a ban on ransom payments, a measure that would make prevention of exposed configurations even more critical. The PNLD has notified the Information Commissioner's Office and is collaborating with the NCA and cybersecurity organizations, but the dossier documents no specific remedial measures adopted nor remediation timelines.

The absence of structured vendor advisories or CVE identifiers for this campaign underscores how the risk stems from implementation design patterns rather than software flaws. The challenge for those managing Power Platform environments is not patching, but verifying that apparently public portals do not expose backend tables with excessive permissions.

Questions and Answers

Is the PNLD the same as the UK's national police database?
No. The PNLD is the Police National Legal Database, a separate service from the Police National Computer and the Police National Database. According to its own breach notice, it does not contain confidential data on victims, witnesses, or offenders.

Why does VenariX mention Power Pages if the root cause is unconfirmed?
VenariX identified Dataverse-consistent structures in the samples examined and one case of a portal without authentication. The link to Power Pages is a probable path, not a definitive conclusion on the specific PNLD breach.

What distinguishes ExfilSquad from other ransomware groups?
The absence of encryption and software vulnerability exploitation in the examined material. The group focuses on exfiltration from misconfigured cloud platforms, a model requiring different skills than traditional ransomware.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. protos.com
  2. cryptonews.net
  3. thehackernews.com
  4. bleepingcomputer.com