Summary
- PNLD confirmed that names, organisations, and work email addresses were compromised and published on the dark web.
- Reporting identifies records associated with the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service.
- PNLD found no evidence that passwords or confidential victim, witness, offender, or case information was involved.
Contact information exposed through the Police National Legal Database extends across police forces, central government, defence, criminal-justice organisations, and members of the public.
PNLD confirmed that names, organisations, and work email addresses belonging to police officers, staff, criminal-justice professionals, government partners, and customers were compromised and published on the dark web.
It found no evidence that passwords or other security credentials were taken. PNLD provides legal information and is not a crime-recording system, meaning it does not hold confidential records about victims, witnesses, or offenders.
The organisation also hosts Ask the Police, a public-facing service that allows people to submit policing and legal questions. Names and email addresses belonging to some previous users of that service were included in the published material.
Reporting based on analysis of the data identifies 114,000 PNLD subscriber records and approximately 21,000 Ask the Police users. It also identifies contacts associated with the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service.
Those numbers have not been published in PNLD’s own notice and remain dependent on external analysis. The official statement does, however, confirm that government partners and customers were among the affected groups.
The broader organisational exposure materially extends Cyber Insider’s initial coverage of the PNLD breach. The incident maps relationships across several parts of the justice and government system rather than exposing only a list of police personnel.
Work contact details do not provide direct access to an account, but they can support targeted impersonation. A message using the correct name, department, professional role, and work address can be tailored around a plausible case, policy request, system notification, or inter-agency process.
The information may carry additional consequences for people working in sensitive or less publicly visible roles. Force or organisational affiliations can be combined with professional networks, public records, social media, or earlier breaches to construct a fuller profile.
The incident also exposes the security value of directories and shared administrative platforms. A system may contain no criminal case files or operational intelligence while still documenting who works with particular forces, agencies, and government bodies.
PNLD detected the incident on 26 July and has engaged specialist cybersecurity organisations and the National Crime Agency. It contacted affected organisations and notified the Information Commissioner’s Office.
A group using the name ExfilSquad has claimed responsibility. PNLD has not attributed the incident publicly, and the group’s statements about its access method and the full quantity of data should remain unverified.
The current evidence supports a large contact-data breach and public release of the information. It does not support claims that police case systems, passwords, or broader government authentication environments were compromised.



