{"id":2180,"date":"2026-08-03T13:30:07","date_gmt":"2026-08-03T13:30:07","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2180"},"modified":"2026-08-03T13:30:07","modified_gmt":"2026-08-03T13:30:07","slug":"pnld-breach-exposes-u-k-police-and-government-contact-details-on-dark-web","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2180","title":{"rendered":"PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 03, 2026<\/span><\/span><span class=\"p-tags\">Data Breach \/ Dark Web<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguFnLbEr199EuLksobp-I8Z6liAUmM4EKRi94ttPtanQN2aiwvNh1qHK_kkGhOBfWTzLzANlQ3jd6FmJOHWbdn8rFfg1sHvYqmBaVM5kfak1JxRhqPEfNR94zY_pibMdsbWMIx8gqcZZjoYLhKk03Gw3PrYKF6JQzrNLV6HiE5U7UtYPSwmH-OmDmjl8c\/s1700-e365\/exfilsquad.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.<\/p>\n<p>The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.<\/p>\n<p>The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police. That exposure could make phishing messages targeting named officers appear more convincing, according to <a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/data-breaches\" target=\"_blank\">UK government guidance<\/a>.<\/p>\n<p>PNLD said, \u00abThere is no evidence to suggest that passwords or other security credentials have been compromised.\u00bb The service provides legal information, products and services to UK police forces and criminal justice organisations. It is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not hold confidential information about victims, witnesses or offenders.<\/p>\n<p>PNLD says it contacted all affected organisations and provided them with further information and guidance. Affected Ask the Police users have already received an email with more information and guidance. It notified the Information Commissioner&#8217;s Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organisations.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As of August 3, 2026, it had not publicly disclosed how many people were affected, when the intrusion began, how long access lasted, or how much information was taken.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>PNLD&#8217;s <a href=\"https:\/\/www.pnld.co.uk\/~\/article\/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f\" target=\"_blank\">official breach notice<\/a> describes the exposed fields but provides no victim total. PNLD reported 108,429 police registrations and support for all 43 Home Office police forces in its <a href=\"https:\/\/www.pnld.co.uk\/assets\/Annual-Summary-25-26\" target=\"_blank\">2025-26 annual summary<\/a>. That is a user-base figure, not a breach-victim count.<\/p>\n<p>PNLD said in its <a href=\"https:\/\/www.pnld.co.uk\/assets\/annual-summary-2023-24\" target=\"_blank\">2023-24 annual summary<\/a> that the database uses Microsoft Power Platform technology. The Hacker News confirmed on August 3, 2026, that the breach-notice page referenced assets hosted on Microsoft&#8217;s content.powerapps.com domain. That corroborates the platform connection but does not show how the attacker obtained the data.<\/p>\n<p><a href=\"https:\/\/venarix.com\/blog\/exfilsquad-targets-misconfigured-microsoft-power-pages-portals\" target=\"_blank\">VenariX reviewed<\/a> samples associated with 11 of <b>ExfilSquad<\/b>&#8216;s 15 claimed victims and found Dataverse-consistent structures across all 11. In the Houston case, it confirmed that a public portal returned records without authentication and that those records were consistent with data published by the group.<\/p>\n<p>VenariX assessed the likely campaign-level path as a public Power Pages site with broad Anonymous Users access to Dataverse tables. The path also required an <a href=\"https:\/\/learn.microsoft.com\/en-us\/power-pages\/configure\/webapi-how-to\" target=\"_blank\">enabled Power Pages Web API<\/a> or legacy OData feed.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/power-pages\/security\/assign-table-permissions\" target=\"_blank\">Microsoft&#8217;s documentation<\/a> says granting the Anonymous Users role access to a table makes its data visible to anyone visiting the site. Its <a href=\"https:\/\/learn.microsoft.com\/en-us\/power-pages\/configure\/web-api-overview\" target=\"_blank\">Web API documentation<\/a> says the \/_api interface follows the table permissions attached to each web role.<\/p>\n<p>VenariX said the evidence \u00abdoes not yet confirm that every organization was affected through an exposed Power Apps portal or the same configuration issue.\u00bb As of August 3, 2026, neither PNLD&#8217;s notice nor VenariX&#8217;s report identified a PNLD-specific endpoint, permission setting, API route, or supporting log.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach.<\/p>\n<p>Microsoft provides a <a href=\"https:\/\/learn.microsoft.com\/en-us\/power-pages\/security\/disable-anonymous-access\" target=\"_blank\">tenant-level governance control<\/a> that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions.<\/p>\n<p>VenariX recommends that Power Pages operators also review Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validate access from an unauthenticated browser session. Those measures address the configuration pattern identified by VenariX, not a confirmed PNLD root cause.<\/p>\n<p>ExfilSquad <a href=\"https:\/\/www.ransomlook.io\/group\/exfilsquad\" target=\"_blank\">listed PNLD on its leak site<\/a> on July 26, but PNLD has not attributed the incident to the group. VenariX found no evidence of ransomware deployment, malware use, lateral movement or exploitation of a software vulnerability in the campaign material it examined.<\/p>\n<p>PNLD has not publicly disclosed the exact access route, the number of unique people affected or the full volume of data published.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Aug 03, 2026Data Breach \/ Dark Web The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2181,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[278,2859,387,1065,985,385,2858,1199,971,213],"class_list":["post-2180","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-breach","tag-contact","tag-dark","tag-details","tag-exposes","tag-government","tag-pnld","tag-police","tag-u-k","tag-web"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2180","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2180"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2180\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2181"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2180"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2180"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2180"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}