UK Police Legal Database Breach Exposes 135,000 Records

06.08.2026 5 min 9

A legal reference service used by every police force in England and Wales has confirmed that its records were stolen and dumped on a dark web leak site. The Police National Legal Database holds no case files and no criminal records, yet the breach still exposed roughly 135,000 records, and among them are ordinary members of the public whose only mistake was asking the police a question.

What was actually taken

The Police National Legal Database, known as PNLD, is run by West Yorkshire Police and works as a legal knowledge base for officers and criminal justice staff across the United Kingdom. The intrusion was detected on 26 July 2026, and a group calling itself ExfilSquad later posted samples on a leak site. PNLD confirmed the theft publicly on 3 August.

  • 114,000 records: subscriber accounts belonging to police officers and other criminal justice professionals.
  • 21,000 records: names and email addresses of people who used Ask the Police, the public facing service where anyone can put a question to the police.
  • 1.9 GB: the volume ExfilSquad claims to hold, which it describes as roughly 135,000 contacts.
  • The fields: full names, work email addresses and the organisation each person works for.

Who is in the file

Because PNLD serves the whole criminal justice system rather than a single force, the affected population is unusually broad. Reporting puts all 43 Home Office police forces in England and Wales in scope, along with British Transport Police, and individual records reach into the Ministry of Defence, the Home Office, the Crown Prosecution Service and the National Crime Agency.

The investigation is led by the North East Regional Organised Crime Unit with support from specialist cyber security firms and the National Crime Agency, an awkward arrangement given that NCA personnel appear among the people whose details were published. The Information Commissioner's Office has been notified.

What was not taken, and why that matters

Accuracy cuts both ways in a breach story, and several things were not exposed. PNLD states there is no evidence that passwords or other security credentials were compromised. No confidential victim, witness or offender information was involved, because the database does not hold that material in the first place. No ransom demand has been received, which is itself notable and suggests a group interested in reputation or resale rather than extortion.

Important: a list without passwords is not a harmless list. Names paired with employers and working email addresses are the raw material for targeted phishing, and the recipients here are people who routinely receive legal and operational correspondence. A convincing message referencing a real force and a real colleague is far easier to write when the attacker already knows both.

Why a roster of police email addresses has value

Stolen consumer databases are usually monetised in bulk. A directory of criminal justice staff is different, because it is small, verified and specific. It maps who works where, it survives password resets, and it stays useful for years, since work addresses and employers change slowly. For anyone attempting social engineering against a force, or simply trying to identify officers, that structure is worth more than a much larger dump of shopping accounts.

There is a second group here that has received far less attention. Ask the Police exists so that a member of the public can ask about their rights, a dispute or an incident without walking into a station. People who used it had a reasonable expectation that the question would stay between them and the service. Their addresses are now in the same file as the officers.

What an individual can and cannot do about this

The uncomfortable part is how little agency anyone had here. Nobody chose to place their details in PNLD; officers were enrolled by their employer and the public used a service the police themselves provided. There was no privacy setting to tighten, no account to delete in advance and no way to audit how the data was held.

That is also the limit of what a network tool can fix. Encrypting a connection protects what travels between a device and a service, and it does nothing about a database that already holds a name and an employer, which is why the practical response to this kind of incident is watching for targeted phishing and treating unexpected work correspondence with suspicion, rather than reaching for a technical fix that does not apply.

Conclusion: the numbers here are modest by breach standards, and the sensitivity is not. A verified roster of who polices what, published alongside the contact details of citizens who asked that same institution for help, is a targeting aid rather than a commodity dataset. The people affected did not hand over this information to a company they chose, which is exactly why the standard advice to be careful what you share does not reach them.

ukunited kingdomdata breachpoliceprivacycybersecuritysecuritycredentialsdark webexfilsquadpnldwest yorkshire policeask the policenational crime agencyicoministry of defencehome officecrown prosecution servicebritish transport policedepartment for education

Read also