UK Police and Government Contact Information Exposed in PNLD Data Breach
A data breach has exposed contact information for UK police and government personnel in the PNLD database. The incident was discovered on July 26, 2026, and involved a misconfiguration of a Microsoft Power Platform/Power Pages portal. This allowed anonymous users to access backend Dataverse tables containing sensitive contact information.
The compromised data set includes names, organisations, and work email addresses of police officers, staff, criminal justice professionals, government partners, and customers. Some members of the public who interacted with the Ask the Police service were also affected.
The threat actor ExfilSquad claimed responsibility for the breach, posting data samples on a leak site and demanding payment from both PNLD and the Department for Education (DfE). The group's tactics are consistent with data extortion operations, focusing on exfiltration and ransom demands rather than destructive activity.