Hackers Claim They Stole a Directory of 135,000 UK Police Contacts

A new hacking group claims it stole 135,000 records from a UK police platform, exposing contact details that could support phishing and impersonation.

Aug 4, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A breach of a UK police legal platform may have exposed a valuable targeting resource: verified contact information belonging to police officers, criminal justice staff, and government partners.

A previously unknown group calling itself ExfilSquad claims it stole roughly 135,000 records from the Police National Legal Database and has published samples on a dark web site. PNLD has confirmed that names, organizations, and email addresses were affected, although the full scope of the attackers’ access remains under investigation.

The exposed information may not include operational case files, but it could support convincing phishing, impersonation, credential theft, and social-engineering attacks against law enforcement personnel.

What data was exposed

The compromise was detected on Sunday, July 26. According to BleepingComputer, ExfilSquad published samples of the stolen data on its dark web site. The group claims it accessed 1.9 GB of PNLD’s data, and has demanded ransom to prevent other records from being released.

Aside from police offciers, PNLD reported that other affected individuals include police staff, criminal justice professionals, and government partners. 

Some members of the public who used the Ask the Police platform to submit questions also had their names and email addresses compromised. Ask the Police is a public-facing service that lets users submit questions about policing and the law.

An increased focus on government organizations

The attack on PNLD adds to a growing list of cyber incidents targeting government organizations, which continue to attract threat actors because they often contain sensitive data and support critical public services. 

According to The Telegraph, Tiff Lynch, chair of the Police Federation, said the breach raised “serious concerns” about the safety of officers and staff. She argued that the police force and its partners “must be properly funded to ensure the strongest possible cybersecurity protections are in place to safeguard sensitive personal data” as cyber threats become increasingly sophisticated.

The breach follows another recent U.K. public-sector incident involving the Department for Education, which exposed approximately 607,000 records. Together, the cases underscore the need to secure public-facing and administrative platforms that may appear less sensitive than core government systems.

Advertisement

A different kind of security risk

Data extortion campaigns derive their leverage from the threat of public exposure. In its message to PNLD, ExfilSquad noted that once the data is up, it is up forever, adding that meeting its financial demand would cost less than the legal consequences and litigation that could follow a public leak. 

While that claim is intended to pressure victims into paying, it reflects how modern cyber extortion increasingly targets an organization’s reputation, regulatory obligations, and long-term financial exposure rather than its ability to restore encrypted systems.

Once stolen data is published, organizations often lose control over where it spreads, increasing the risks from a single compromise. 

The risks are not theoretical. Earlier this year, a breach at the Los Angeles City Attorney’s Office led to the online publication of thousands of confidential LAPD records, exposing sensitive documents linked to police personnel and civil litigation. 

The incident sparked criticism from police representatives and raised the prospect of further legal action, illustrating how the impact of a data leak can continue well after the initial compromise has been contained. For enterprises, this creates a strong incentive to prioritize preventive cybersecurity and, if a compromise occurs, significantly reduce the severity of an attack.

Other News: Black Hat USA 2026 speakers urged CISOs to replace technical dashboards with business-focused cyber risk reporting.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.