← BACK TO FEED
data breachExfilSquadUK public sectorcybercrimeransomware

ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree Continues

The Police National Legal Database (PNLD) has confirmed a data breach in which cybercriminals stole names, organisations, and work email addresses belonging to police officers, criminal justice staff, government partners, and customers, with no evidence that passwords were compromised. The breach is linked to an extortion group called "ExfilSquad," which claims to have stolen a 1.9 GB dataset containing around 135,000 law enforcement contact records, and also claimed responsibility for a recent breach of the UK Department for Education affecting over 607,000 records. Key details — including how attackers gained access, the exact number of victims, and whether a ransom was demanded — have not yet been disclosed.

The Police National Legal Database has joined a growing list of UK public sector organisations forced to admit their data ended up somewhere it shouldn't. PNLD, the legal reference service used by police forces and criminal justice agencies across the country, confirmed on July 26 that attackers had walked off with staff contact data including names, work email addresses, and organisational details belonging to police officers, justice professionals, and government partners.

West Yorkshire Police, which runs the service, says it is investigating alongside specialist cybersecurity firms and the National Crime Agency. It maintains there is no evidence that passwords or authentication credentials were taken. Small mercies.

The breach also touched Ask the Police, PNLD's public-facing legal advice site. Anyone who previously submitted a question through it may find their name and email address in the hands of criminals. The organisation has not disclosed how the attackers got in, when the theft actually occurred, or how many people are affected in total. Requests for further comment went unanswered.

The group behind the attack appears to be ExfilSquad, the same extortion crew that claimed responsibility last week for a breach at the Department for Education. The gang lists both organisations as victims on its dark web leak site. For PNLD, it claims a 1.9 GB haul containing roughly 135,000 law enforcement contact records. The DfE listing is larger, boasting around 600,000 parent and staff records plus a further 7,000 from the Turing Portal. The DfE has since confirmed that more than 607,000 records were exposed, drawn from its Customer Help Portal and Turing Scheme.

ExfilSquad's leak site leans into the usual theatrics. Victims are told their data is "NEVER leaving the public eye" and invited to consider whether a ransom might be cheaper than the legal fallout. Standard fare for this kind of operation.

The gang also lists Microsoft among its victims, claiming a 13 GB dataset containing millions of records, password hashes, internal support tickets, and access permissions. That one remains unconfirmed.

Two confirmed breaches in quick succession does make ExfilSquad harder to dismiss as noise. Whether the Microsoft claim and any others on their site reflect genuine intrusions or are embellished to inflate the group's reputation is another matter entirely. The pattern of targeting public sector organisations sitting on large contact databases is worth watching.

READ NEXT
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to PayAmerican Bank Trusts Ransomware Gang's Pinky Promise to Delete Stolen DataStadler Rail Tells Ransomware Gang to Take a Hike on a CHF 10 Million Demand