ExfilSquad claims it stole 135,000 contact records from the U.K.'s Police National Legal Database (PNLD), a cache the group says totals roughly 1.9 GB of data.
What the attackers say they took
The data-extortion group ExfilSquad published sample material and claimed responsibility for an intrusion that, according to the group, included approximately 1.9 GB of data composed of roughly 135,000 records. ExfilSquad split that figure into about 114,000 PNLD subscribers and 21,000 users of the public “Ask the Police” site. The service confirmed that the breach publicly exposed full names, organizations, and email addresses of police officers, staff, criminal justice professionals and government partners, and also the names and email addresses of Ask the Police users who submitted questions.
PNLD’s role and the scope of what it stores
PNLD is an online legal resource used for more than 30 years by the 43 Home Office police forces in England and Wales and by the British Transport Police. It also operates Ask the Police, a public website with answers to hundreds of common policing and legal questions. PNLD has said it does not hold confidential information relating to victims, witnesses, or offenders, and that no such data was impacted in this incident.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Detection, notification, and ongoing investigation
The intrusion was detected on Sunday, July 26. PNLD says the incident is being investigated with assistance from cybersecurity experts and the National Crime Agency (NCA). The service reported that “no evidence has been found that passwords or other security credentials have been compromised.” PNLD also stated, “All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner’s Office (ICO) has also been notified.” PNLD has confirmed the breach and the publication of contact details but has not publicly attributed the intrusion or disclosed how attackers gained access.
ExfilSquad’s pattern and the ransom claim
ExfilSquad published sample records to support its claim and demanded a ransom in exchange for not releasing additional stolen data, according to the reporting. The group is the same threat actor that recently claimed an attack on the American semiconductor company Analog Devices, a point noted by coverage of the PNLD incident.
How police forces, Ask the Police users, and regulators are positioned
- Police forces and criminal justice professionals: PNLD says it contacted all affected organizations and provided them with further information and guidance; those organizations will be working with PNLD, the NCA and cybersecurity experts as the investigation continues.
- Ask the Police users: The names and email addresses of users who submitted questions through the platform are among the records ExfilSquad claims to have taken; those users are identified in the published sample data and may require communications from PNLD or their organizations as the response unfolds.
- Regulators and investigators: The Information Commissioner’s Office (ICO) has been notified and the National Crime Agency is assisting the probe, per PNLD’s statement.
The facts on hand are straightforward and narrow: contact information appears to have been exposed, PNLD has engaged external cybersecurity expertise and law enforcement, and a known data-extortion group has claimed both responsibility and reward. What remains publicly undisclosed is exactly how the attackers gained access and whether further sensitive material beyond names, organizations and email addresses exists. The coming days will hinge on the progress of the NCA-assisted investigation, any technical details PNLD releases about the vector of compromise, and whether ExfilSquad publishes more of the dataset it says it holds.
Original reporting: BleepingComputer: ExfilSquad hackers leak info of over 100,000 UK police officers, staff




