Breach Analysis·6 August 2026

Police Legal Database Breach Exposes More Than 100,000 Officers and Staff

A cyber attack on the Police National Legal Database has exposed the names, organisations and work email addresses of more than 100,000 police officers, police staff and criminal justice professionals. The extortion group ExfilSquad claims around 135,000 records.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Dimly lit police records office at night with rows of legal reference binders, a police lanyard on the desk and an unplugged network cable beside a dark monitor
Breach Analysis

Article record

Breach AnalysisCategory
6 August 2026Published
4 min readReading time
Mark FermorWritten by
Dimly lit police records office at night with rows of legal reference binders, a police lanyard on the desk and an unplugged network cable beside a dark monitor

Why it matters

What this means for organisations holding critical data

A cyber attack on the Police National Legal Database has exposed the names, organisations and work email addresses of more than 100,000 police officers, police staff and criminal justice professionals. The extortion group ExfilSquad claims around 135,000 records.

The contact details of more than 100,000 police officers, police staff and criminal justice professionals have been exposed following a cyber attack on the Police National Legal Database (PNLD), the legal reference service used by all 43 Home Office police forces in England and Wales as well as the British Transport Police. The breach was reported by Computing on 4 August 2026.

What Happened

PNLD detected the intrusion on 26 July and has since confirmed that names, organisations and work email addresses of police officers, police staff, criminal justice professionals and government partners were accessed. The names and email addresses of members of the public who submitted questions through the Ask the Police website were also compromised.

The service states that the database does not contain confidential information about victims, witnesses or offenders, and that there is no evidence that passwords or other login credentials were accessed. Affected organisations have been notified and the Information Commissioner's Office has been informed. The National Crime Agency and external cyber security specialists are assisting with the investigation.

The data extortion group ExfilSquad has claimed responsibility, saying it took around 1.9GB of data containing approximately 135,000 records, of which about 114,000 relate to PNLD subscribers and 21,000 to users of Ask the Police. A sample has been published online and a ransom demanded for the remainder.

Why It Matters

A verified list of serving police officers and criminal justice professionals, complete with organisation and work email address, is not ordinary contact data. It is a targeting list. One police staff member whose details were exposed told The Times that the leak was deeply unsettling because of their work against serious organised crime.

For officers involved in sensitive investigations, exposure of identity and employer is a personal safety issue as much as a data protection one. For everyone else on the list, it is the raw material for convincing phishing and impersonation, because an attacker who can appear to be a trusted legal reference service or a colleague in another force has a very short route into systems that hold far more sensitive material.

A Pattern Across the Public Sector

This incident follows the Department for Education breach, in which around 607,000 records were exposed in an attack also claimed by ExfilSquad. UK Government Investments has separately disclosed a breach that left internal information and the work contact details of dozens of officials exposed online for close to 48 hours.

Graham Taylor, Director of Defence Strategy for Northern Europe at OPSWAT, said the immediate priority should be protecting officers whose identities have been exposed, particularly those involved in organised crime investigations, and added: "The uncomfortable truth is that much of the UK's public sector, with significant legacy systems and fragmented oversight, is years behind the resourcing and resilience needed to combat current and future cyber threats."

The Firevault View

Mark Fermor, founder of Firevault, said: "Three decades of subscriber records sitting behind a permanently connected reference service is a very large amount of data kept reachable for a very small amount of daily need. The question every force and every public body should be asking is not how to defend everything, but which records have no reason to remain permanently reachable at all."

Offline Secure Storage® answers that question at Layer 1. Records placed in an offline vault are physically disconnected at the hardware level, so they cannot be scanned, read, altered, encrypted or exfiltrated by an attacker who already has a foothold in an online estate. Subscriber and personnel directories, historic case material, archived legal reference sets and governance papers do not need a permanent network path in order to be useful.

For public sector environments where operational systems must stay online, Firevault Control provides the physical isolation layer around the data those systems depend on. Disconnect to Protect®.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis6 August 20264 min read

Police Legal Database Breach Exposes More Than 100,000 Officers and Staff

A cyber attack on the Police National Legal Database has exposed the names, organisations and work email addresses of more than 100,000 police officers, police staff and criminal justice professionals. The extortion group ExfilSquad claims around 135,000 records.

Police Legal Database Breach Exposes More Than 100,000 Officers and Staff
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy