The full names and details of more than 100,000 police staff have been leaked on the dark web in a hack which has put officers at “serious risk”.
Cyber criminals compromised data from the Ministry of Defence , the Office, National Crime Agency (NCA) and Crown Prosecution Service (CPS), The Times reported.
It follows a hack on the Department for Education (DfE) last week, which had led to more than half a million pieces of data being compromised.
Hackers leaked officers’ force location after breaching the police national legal database (PNLD), an online resource used by all Office police forces in the UK to provide legal assistance.
The cyber criminal group ExfilSquad is understood to be responsible for the cyberattacks and have hacked several Western systems in recent weeks.
One member of staff whose details were leaked told the newspaper: “I have worked in serious organised crime and put high-level criminals behind bars. For private information to be leaked me is very disconcerting and puts officers at serious risk.
“In the past I have been forced to move into safe houses and sell cars due to my job. Now I will have to keep my wits me online and look out for anyone trying to get more serious information. It is not a good look.”
The DfE hack led to 607,000 pieces of data being released on the dark web and was thought to have been carried out for financial gain rather than ideological reasons.
The group said online: “Once your company’s data is posted here, it’s NEVER leaving the public eye and it will be passed around the internet FOREVER. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.”
One source said the majority of officers have used the legal database during their career to complete day-to-day police duties.
The system is responsible for England and Wales, where 145,550 full-time officers are employed,.
Tiff Lynch, chairman of the Police Federation , said: “This reported breach raises serious concerns for officer and staff safety. At a time when cyber threats are becoming increasingly sophisticated, [the police] and its partners must be properly funded to ensure the strongest possible cybersecurity protections are in place to safeguard sensitive personal data.”
Jake Moore, global security adviser at Eset, Europe’s leading cybersecurity company, said: “Unfortunately government organisations are being seen as softer targets because they have not invested enough to properly protect private information.
“The information put on the dark web should not be underestimated. More experienced threat actors see it as highly valuable because it enables them to personalise follow-up attacks, such as phishing or social engineering, which puts even more data at risk.”
Newcastle University has launched an investigation after the group allegedly stole 440,000 pieces of sensitive data including full names, phone numbers, addresses and email addresses of staff and students.
Mr Moore added: “These attacks are becoming more common as criminals increasingly automate their tactics with ease and exploit the development using AI. The knock-on effect means organisations are facing a far higher volume of attacks, often with far less effort required from the attacker.”
A government spokesman said: “We have dedicated capabilities to respond to cyber incidents, and it would be inappropriate to on a live investigation.”
An NCA spokesman told The Times: “We are aware that limited personal details relating to a number of National Crime Agency officers may have been published on the dark web as a result of the incident affecting the police national legal database.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
