PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government, and customer contact information was compromised and published on the dark web. The data included names, organisations, and work email addresses belonging to police officers, police staff, cr…
Intelligence analysis by Llama

A breach in the Police National Legal Database (PNLD) has exposed contact details of U.K. police and government officials on the dark web. The compromised data includes names, organisations, and work email addresses.
Imagine you're at a big conference, and someone steals a list of all the attendees' names, job titles, and email addresses. That's basically what happened in this data breach. The list included police officers, government officials, and other people who work with the police. The thief put the list on the dark web, which is like a secret internet where people can buy and sell stolen information.
Analysis
A $60B Vote of Confidence
The breach in the Police National Legal Database (PNLD) has exposed contact details of U.K. police and government officials on the dark web. The compromised data includes names, organisations, and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners, and customers. The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police.
The data breach has raised concerns about the security of sensitive information in the public sector. The PNLD provides legal information, products, and services to UK police forces and criminal justice organisations. It is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not hold confidential information about victims, witnesses, or offenders.
The service contacted all affected organisations and provided them with further information and guidance. Affected Ask the Police users have already received an email with more information and guidance. It notified the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organisations.
As of August 3, 2026, it had not publicly disclosed how many people were affected, when the intrusion began, how long access lasted, or how much information was taken. PNLD's official breach notice describes the exposed fields but provides no victim total. PNLD reported 108,429 police registrations and support for all 43 Home Office police forces in its 2025-26 annual summary. That is a user-base figure, not a breach-victim count.
Why Cursor?
VenariX reviewed samples associated with 11 of ExfilSquad's 15 claimed victims and found Dataverse-consistent structures across all 11. In the Houston case, it confirmed that a public portal returned records without authentication and that those records were consistent with data published by the group. VenariX assessed the likely campaign-level path as a public Power Pages site with broad Anonymous Users access to Dataverse tables.
The path also required an enabled Power Pages Web API or legacy OData feed. Microsoft's documentation says granting the Anonymous Users role access to a table makes its data visible to anyone visiting the site. Its Web API documentation says the /_api interface follows the table permissions attached to each web role. VenariX said the evidence 'does not yet confirm that every organization was affected through an exposed Power Apps portal or the same configuration issue.'
The Road Ahead
As of August 3, 2026, neither PNLD's notice nor VenariX's report identified a PNLD-specific endpoint, permission setting, API route, or supporting log. At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach. Microsoft provides a tenant-level governance control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions. VenariX recommends that Power Pages operators also review Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validate access from an unauthenticated browser session.
Key points
- The Police National Legal Database (PNLD) has confirmed a data breach that exposed contact details of U.K. police and government officials on the dark web.
- The compromised data includes names, organisations, and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners, and customers.
- PNLD has contacted all affected organisations and provided them with further information and guidance.
- The Information Commissioner's Office (ICO) and the National Crime Agency (NCA) are working with PNLD to investigate the breach.
If the authorities can identify the source of the breach and take steps to prevent similar incidents in the future, this could lead to improved security measures for sensitive information in the public sector.
The breach could lead to phishing attacks targeting named officers, making it easier for hackers to trick them into revealing sensitive information.


