The UK's Police National Legal Database (PNLD) and the Department for Education (DfE) have both been impacted by data breaches. The cyber extortion group ExfilSquad has claimed responsibility for these incidents, demanding a ransom in exchange for not releasing the compromised information.
The PNLD breach, detected on July 26, exposed contact data for over 100,000 police officers, staff, and criminal justice professionals. Separately, the DfE reported that over 600,000 lines of data were compromised from its Help Desk Self-Service Portal and Turing Scheme Portal.
The PNLD confirmed that police, government, and customer contact information was compromised and subsequently published on the dark web. This data included names, organizations, and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners, and customers.
The incident also exposed names and email addresses of individuals who submitted questions through 'Ask the Police'. PNLD stated there is no evidence that passwords or other security credentials were compromised. The service provides legal information to UK police forces and criminal justice organizations and does not hold confidential information about victims, witnesses, or offenders.
Cybercriminals are attempting to extort the Department for Education after compromising what they described as more than 600,000 pieces of data. A DfE spokesperson clarified that this number refers to lines of data, not the count of individuals affected, and that the risk to individuals is not considered high.
The impacted portals were the DfE Help Desk Self-Service Portal and the Turing Scheme Portal. The DfE spokesperson did not confirm the specific types of data compromised but the criminals alleged it included names, email addresses, and phone numbers.
ExfilSquad, the group claiming responsibility, is demanding a ransom to prevent the release of the stolen data. There is no claim that the hackers encrypted the compromised systems. The Home Office declined to comment on the PNLD breach.
The PNLD incident is currently under investigation with assistance from cybersecurity experts and the National Crime Agency (NCA). PNLD has contacted all affected organizations and provided guidance.
The exposure of contact details, particularly for law enforcement and criminal justice professionals, could facilitate more convincing phishing attacks. While no passwords were compromised, the availability of names and work email addresses could be used to craft targeted social engineering attempts. The DfE stated the risk to individuals from their breach is not considered high.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The UK's Police National Legal Database (PNLD) experienced a cyberattack, leading to the compromise of contact data for over 100,000 police officers, staff, and criminal justice professionals. The ExfilSquad data extortion group claimed responsibility, publishing sample data and demanding a ransom. This incident highlights ongoing vulnerabilities in public sector data management and the persistent threat of data extortion.
The Police National Legal Database (PNLD) confirmed a data breach that exposed contact information for UK police, government partners, and customers, which was subsequently published on the dark web. This incident is significant because the exposed data, including names and work email addresses, could facilitate more convincing phishing attacks targeting law enforcement and criminal justice professionals.
Cyber extortionists, ExfilSquad, claim to have stolen over 600,000 lines of data from the UK Department for Education (DfE) and 135,000 pieces of data from the Police National Legal Database (PNLD), demanding a ransom. This incident highlights ongoing cyber threats to government entities and the UK's policy against paying ransoms.