The extortion group ExfilSquad claimed responsibility for breaching the U.K. Police National Legal Database (PNLD), a system managed by West Yorkshire Police, and publishing stolen data on the dark web. PNLD said the incident exposed names, organizations, and work email addresses of police officers, staff, criminal justice professionals, government partners, customers, and some users of the Ask the Police service. The group said it stole 1.9GB of data covering roughly 135,000 records, while PNLD said it had found no evidence that passwords or other security credentials were compromised and that the database does not hold confidential information on victims, witnesses, or offenders. Authorities said specialist cybersecurity organizations and the UK National Crime Agency were involved in the investigation and response.
The breach has become a high-profile example of ExfilSquad’s broader hack-and-leak campaign, which targets exposed or misconfigured cloud and SaaS platforms including Microsoft Dataverse, Power Pages, case management systems, and CRM environments. Researchers said the group recently named 13 additional victims across the United States, United Kingdom, and Sweden, and has shifted to torrent-based distribution of stolen data, using unique trackers and web seeds to make takedowns harder and accelerate spread through P2P networks. Reporting also linked active sharing nodes in China and Russia to the leaked PNLD data, underscoring the heightened risk of spear-phishing and social engineering against affected police and justice personnel.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Resecurity reported that on August 7, 2026, torrent-sharing nodes and seeds in China and Russia were among the most active distributing ExfilSquad-linked leaked data, suggesting strong interest or possible prior awareness of the release.
ExfilSquad set August 5, 2026 as the deadline for negotiations with newly listed victims before releasing stolen data.
In a statement dated August 3, PNLD disclosed that police officers, staff, criminal justice professionals, government partners, customers, and some Ask the Police users had data compromised, while saying there was no evidence passwords or other credentials were affected.
The Police National Legal Database said it identified a data security incident on July 26 affecting names, organizations, and work email addresses, with some data later appearing on the dark web.
Reporting said ExfilSquad targeted a major financial institution in Nigeria in July 2026 as part of its expanding victim set.
Security reporting described ExfilSquad as emerging in mid-2026 and operating by stealing data from cloud and SaaS platforms, then threatening publication rather than deploying ransomware.
During the reported week, ExfilSquad announced 13 new victim organizations in the United States, the United Kingdom, and Sweden, reflecting an expansion of its extortion campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.