Personal data for more than 100,000 UK police officers and staff was reportedly leaked on the dark web after a major breach affecting multiple government bodies. Exposed information included full names and contact details, with reporting indicating the incident also impacted the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service, adding to concerns over the exposure of sensitive law-enforcement and government personnel records.
The intrusion has been attributed in reporting to the cybercriminal group ExfilSquad, which allegedly listed the victims on its leak site and claimed the access stemmed from Microsoft Power Apps and Dynamics 365 misconfigurations. Specifically, the group said improperly configured permissions on Dataverse tables enabled the data exposure, and the breach was reported after a separate recent compromise involving the Department for Education.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Police National Legal Database said it detected a cyberattack on July 26 and confirmed that names, organizations, and email addresses of more than 100,000 police officers, criminal justice professionals, government partners, and Ask the Police users were exposed. PNLD said affected organizations were notified, the ICO was informed, and the National Crime Agency was assisting the investigation.
ExfilSquad listed the Police National Legal Database on its leak site on July 26, claiming it stole about 1.9 GB of data covering roughly 135,000 records, including subscriber and Ask the Police user data. The group said it would release remaining material unless a ransom was paid, though PNLD did not confirm the attribution.
Full names and contact details of more than 100,000 UK police officers and staff were reportedly published on the dark web following the breach. The exposed dataset was described as part of a major security incident affecting UK government and law-enforcement personnel information.
In a separate incident described as occurring the previous week, more than half a million pieces of Department for Education data were reportedly compromised. The reference presents this as distinct from the broader UK government breach.
Hackers believed to be ExfilSquad reportedly compromised data belonging to several UK government entities, including the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service. The group was also said to have attributed the victims on its leak site to Microsoft Power Apps and Dynamics 365 misconfigurations involving Dataverse table permissions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.