The PNLD breach (Police National Legal Database) is one of the most serious data breaches to hit British law enforcement in recent years. According to an official announcement, the names, organizations and work email addresses of police officers, government officials and criminal justice professionals were exposed and published on the dark web, putting thousands of people working in the public safety sector in Britain at risk.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web

The breach was discovered on 26 July 2026 , when the ExfilSquad group uploaded the stolen data to a dark web leak site. The exposed data includes more than 114,000 PNLD subscribers , as well as 2,615 Crown Prosecution Service ( CPS) employees , 617 Home Office employees , 588 National Crime Agency (NCA ) employees and 402 Ministry of Defence employees . In addition, around 21,000 email addresses of citizens who had submitted questions through the Ask the Police service were also exposed, with the total leaked file estimated to be around 1.9 GB unzipped.
The PNLD is a legal information service that serves police forces and criminal justice agencies across England and Wales. It is important to clarify that it is not the Police National Computer or the Police National Database, is not a crime recording system and does not hold confidential information about victims, witnesses or perpetrators. However, the disclosure of police officers' work contact details poses serious risks as it can be used for targeted phishing against officers.
PNLD breach: Technical analysis and the role of Microsoft Power Platform
PNLD's breach announcement page referenced assets hosted on Microsoft 's content.powerapps.com domain , confirming the connection to Microsoft Power Platform . PNLD had stated in its 2023-24 annual report that the database uses Microsoft Power Platform technology . Cybersecurity firm VenariX analyzed samples associated with 11 of the 15 victims claimed by ExfilSquad and found structures consistent with Dataverse in all cases.
VenariX assessed that the most likely attack path at the campaign level was a public Power Pages website with overly broad Anonymous Users access to Dataverse tables , combined with an enabled Power Pages Web API or legacy OData feed . Microsoft documentation explicitly states that granting access to the Anonymous Users role on a table makes its data visible to anyone visiting the site. This means that the issue may have been primarily a matter of misconfiguration and access control, and not necessarily a zero-day exploit or strong authentication bypass.
In the case of Houston (one of the other victims analyzed by VenariX), it was confirmed that a public portal was returning unauthenticated records, and that these records were consistent with the data published by the team. However, VenariX emphasized that the evidence does not yet confirm that every organization was affected by an exposed Power Apps portal or the same configuration issue. The connection to Power Pages remains a case under investigation and not a confirmed cause of the PNLD breach.
See also: FortiBleed Foreign Office: UK Credentials on the Dark Web

PNLD breach: Impact and reactions of the authorities
The PNLD has contacted all affected organisations and provided them with further information and guidance. Affected users of the Ask the Police have already received emails with relevant information. The service has informed the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cyber security organisations. Importantly, the PNLD said there is no indication that passwords or other security credentials have been compromised.
ExfilSquad also claimed responsibility for a breach of the Department for Education (DfE) , with reports describing around 607,000 records from help-desk and Turing Scheme portals. The DfE said no banking details or highly sensitive data were involved. VenariX found no evidence of ransomware deployment, malware use or lateral network traffic, suggesting this was a data exfiltration and extortion attack, rather than a classic encryption attack.
The incident is part of a broader pattern of cloud application and portal breaches where flawed access controls or publicly exposed low-code components lead to mass data extraction rather than traditional malware encryption. This reflects a growing trend in cyberattacks where attackers are exploiting misconfigurations in cloud platforms to gain access to large amounts of data without having to bypass strong authentication systems.
Practical recommendations for protection against PNLD breaches
VenariX recommends that Power Pages operators review Anonymous Users table permissions, Web API settings, and legacy OData feeds, and then verify access from an unauthenticated browser session. Microsoft provides a tenant-level governance control that blocks unauthenticated users from reading Dataverse data while still allowing public form submissions. These measures address the configuration pattern that VenariX identified, and not a confirmed root cause for PNLD.
For organizations using similar platforms, key recommendations include: auditing public low-code applications for anonymous access, open tables, and exposed APIs, particularly in Power Pages/Dataverse; limiting anonymous users to the minimum possible dataset and disabling unused APIs, feeds, and connectors; monitoring for patterns of bulk export and unusual access to tables backed by portals, particularly where large contact data sets can be queried without authentication; rotating and auditing secrets, service principals, and integrations connected to exposed portals, even if no password breach is confirmed.
See also: Eurail data breach: Stolen data is being sold on the dark web

The PNLD, for its part, has not publicly attributed the attack to the ExfilSquad, and as of August 3, 2026, it had not publicly disclosed how many people were affected, when the intrusion began, how long the access lasted, or how much information was stolen. The lack of transparency on these critical issues has raised concerns in the cybersecurity community, as timely and complete disclosure is essential to the protection of affected individuals and organizations. The case highlights once again how critical it is to properly configure cloud services, especially when they are used by sensitive public entities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
