Hackers Claim They Stole a Directory of 135,000 UK Police Contacts

A new hacking group claims it stole 135,000 records from a UK police platform, exposing contact details that could support phishing and impersonation.

Aug 4, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A breach of a UK police legal platform may have exposed a valuable targeting resource: verified contact information belonging to police officers, criminal justice staff, and government partners.

A previously unknown group calling itself ExfilSquad claims it stole roughly 135,000 records from the Police National Legal Database and has published samples on a dark web site. PNLD has confirmed that names, organizations, and email addresses were affected, although the full scope of the attackers’ access remains under investigation.

The exposed information may not include operational case files, but it could support convincing phishing, impersonation, credential theft, and social-engineering attacks against law enforcement personnel.

What data was exposed

The compromise was detected on Sunday, July 26. According to BleepingComputer, ExfilSquad published samples of the stolen data on its dark web site. The group claims it accessed 1.9 GB of PNLD’s data, and has demanded ransom to prevent other records from being released.

Aside from police offciers, PNLD reported that other affected individuals include police staff, criminal justice professionals, and government partners. 

Some members of the public who used the Ask the Police platform to submit questions also had their names and email addresses compromised. Ask the Police is a public-facing service that lets users submit questions about policing and the law.

An increased focus on government organizations

The attack on PNLD adds to a growing list of cyber incidents targeting government organizations, which continue to attract threat actors because they often contain sensitive data and support critical public services. 

According to The Telegraph, Tiff Lynch, chair of the Police Federation, said the breach raised “serious concerns” about the safety of officers and staff. She argued that the police force and its partners “must be properly funded to ensure the strongest possible cybersecurity protections are in place to safeguard sensitive personal data” as cyber threats become increasingly sophisticated.

The breach follows another recent U.K. public-sector incident involving the Department for Education, which exposed approximately 607,000 records. Together, the cases underscore the need to secure public-facing and administrative platforms that may appear less sensitive than core government systems.

Advertisement

A different kind of security risk

Data extortion campaigns derive their leverage from the threat of public exposure. In its message to PNLD, ExfilSquad noted that once the data is up, it is up forever, adding that meeting its financial demand would cost less than the legal consequences and litigation that could follow a public leak. 

While that claim is intended to pressure victims into paying, it reflects how modern cyber extortion increasingly targets an organization’s reputation, regulatory obligations, and long-term financial exposure rather than its ability to restore encrypted systems.

Once stolen data is published, organizations often lose control over where it spreads, increasing the risks from a single compromise. 

The risks are not theoretical. Earlier this year, a breach at the Los Angeles City Attorney’s Office led to the online publication of thousands of confidential LAPD records, exposing sensitive documents linked to police personnel and civil litigation. 

The incident sparked criticism from police representatives and raised the prospect of further legal action, illustrating how the impact of a data leak can continue well after the initial compromise has been contained. For enterprises, this creates a strong incentive to prioritize preventive cybersecurity and, if a compromise occurs, significantly reduce the severity of an attack.

Other News: Black Hat USA 2026 speakers urged CISOs to replace technical dashboards with business-focused cyber risk reporting.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.