Back Bleepingcomputer ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised data of more than 100,000 police officers and other criminal justice professionals.
The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 records.
PNLD is an online legal resource service that has been used for more than 30 years by the 43 Office police forces in England and Wales, as well as the British Transport Police.
PNLD also operates ‘Ask the Police,’ a public-facing website with answers to hundreds of common policing and legal questions.
In a statement today, the service says that the breach exposed the full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners.
Also considered compromised are the names and email addresses of Ask the Police users who submitted a question through the platform.
The incident is now being investigated with assistance from cybersecurity experts and the National Crime Agency (NCA). No evidence has been found that passwords or other security credentials have been compromised.
PNLD does not hold confidential information relating to victims, witnesses, or offenders, and says no such data was impacted.
“All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner’s Office (ICO) has also been notified,” PNLD says .
The ExfilSquad data extortion group claimed responsibility for the attack on PNLD and published sample data to support its claims. The threat actor also demanded a ransom in exchange for not releasing the remaining stolen data.
ExfilSquad is the same threat actor that recently claimed an attack on American semiconductor company Analog Devices .
PNLD has confirmed the breach and publication of details but has not publicly attributed the intrusion or disclosed how attackers gained access.
BleepingComputer has contacted PNLD to ask for more details the incident and will update the article when we receive a .
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
