On July 26, 2026, the Police National Legal Database (PNLD) confirmed a significant data breach that resulted in the exposure of police, government, and customer contact details on the dark web. The compromised data included names, organizational affiliations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and other stakeholders.
Scope of the Breach
The breach also affected individuals who had submitted inquiries through the ‘Ask the Police’ platform, potentially making targeted phishing attempts more credible. Despite the exposure, PNLD assured the public that there is no evidence of compromised passwords or other security credentials. The PNLD is distinct from critical systems like the Police National Computer and does not store sensitive information involving victims or offenders.
Response and Investigation
Following the breach, PNLD promptly informed all affected parties and provided necessary guidance. The Information Commissioner’s Office (ICO) was notified, and PNLD is working alongside the National Crime Agency (NCA) and cybersecurity experts to investigate the incident. As of August 3, 2026, PNLD has not disclosed specific details about the breach’s impact, such as the number of affected individuals or the duration of unauthorized access.
Reports indicate that the breach may be linked to a misconfiguration involving Microsoft’s Power Platform technology. VenariX, a cybersecurity firm, found that the breach could involve public access to Dataverse tables through a Power Pages site, although they have not confirmed this as the definitive cause.
Technical Analysis and Recommendations
VenariX’s investigation suggests that a public Power Pages portal with broad permissions might have facilitated unauthorized data access. The firm advises reviewing Anonymous Users table permissions and API settings to prevent similar breaches. Microsoft documentation highlights the risk of exposing data when anonymous access is granted, underscoring the need for strict governance controls.
Although ExfilSquad listed PNLD in its leak disclosures, there is no evidence linking the group to ransomware or malware attacks against PNLD. The exact method by which data was accessed remains under investigation, and PNLD has yet to attribute the breach to any specific party.
As investigations continue, PNLD and its partners are focused on securing data and preventing future incidents. The breach highlights the critical need for robust cybersecurity measures in managing sensitive data.
