PNLD Breach Exposes UK Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) confirmed a data breach exposing contact information of police officers, government staff, and customers, published on the dark web.

The Police National Legal Database (PNLD) has confirmed a significant data breach that resulted in the exposure of contact information for numerous UK police officers, government personnel, and customers. The compromised data, which includes names, organizations, and work email addresses, was discovered on the dark web on July 26. This incident raises serious concerns about the security of sensitive contact details for individuals involved in law enforcement and government operations across the United Kingdom.
In addition to police and government staff, the breach also affected individuals who had submitted questions through the 'Ask the Police' service, exposing their names and email addresses. This specific exposure could potentially make targeted phishing attacks against named officers more convincing, according to guidance issued by the UK government. PNLD has stated that there is currently no evidence to suggest that passwords or other security credentials were compromised in this incident.
The PNLD serves as a vital resource, providing legal information, products, and services to UK police forces and criminal justice organizations. It is crucial to note that PNLD is distinct from the Police National Computer or the Police National Database and does not store crime records or confidential victim or offender information. Despite the confirmation of the breach, PNLD has not publicly disclosed the exact number of individuals affected, the timeline of the intrusion, or the total volume of data exfiltrated.
PNLD has taken steps to notify all affected organizations, providing them with detailed information and guidance. Users of the 'Ask the Police' service who were impacted have also been directly contacted via email with relevant information. The organization has reported the incident to the Information Commissioner's Office (ICO) and is actively collaborating with the National Crime Agency (NCA) and specialized cybersecurity firms to investigate the breach.
Initial analysis suggests a potential link to Microsoft Power Platform technology, as PNLD's annual summary indicated its use of this platform. The breach notice page referenced assets hosted on Microsoft's content.powerapps.com domain, corroborating this connection. However, the precise method by which the attacker gained access to the data remains under investigation.
Security researchers have observed data structures consistent with Microsoft's Dataverse across samples related to the incident. A potential attack vector identified involves a public Power Pages site with broad anonymous user access to Dataverse tables, coupled with an enabled Power Pages Web API or legacy OData feed. Microsoft's documentation indicates that granting the Anonymous Users role access to a table can make its data visible to anyone visiting the site.
While this configuration pattern presents a plausible hypothesis for the breach, it is not yet confirmed as the definitive root cause for the PNLD incident. Neither PNLD's official notice nor the research reports have identified a specific PNLD endpoint, permission setting, API route, or supporting log that directly explains the compromise. Microsoft offers tenant-level governance controls that can prevent unauthenticated users from reading Dataverse data while still allowing public form submissions.
ExfilSquad, an extortion group, listed PNLD on its leak site on July 26, but PNLD has not officially attributed the breach to this group. Current findings from security analysis show no evidence of ransomware deployment, malware usage, lateral movement, or exploitation of a specific software vulnerability in the campaign materials examined, suggesting a potential focus on data exfiltration through misconfiguration.