Information belonging to more than 100,000 police officers and staff has reportedly been published on the dark web following a breach of the Police National Legal Database.
The Police National Legal Database, known as the PNLD, has confirmed that names, organisations and work email addresses belonging to police officers, police staff and other criminal justice professionals were compromised and published online.
The organisation said there was currently no evidence that passwords or other security credentials had been compromised.
Approximately 114,000 subscriber records reportedly exposed
The Times reported that details connected to approximately 114,000 PNLD subscribers had been released, with the vast majority of the records belonging to police officers.
The exposed information reportedly includes full names, official contact details and the force or organisation with which each person is associated.
It is important to distinguish those details from more sensitive personal information. Neither the official PNLD notice nor the reporting reviewed for this article indicates that officers' home addresses, personal telephone numbers or financial information were contained in the published PNLD records.
What is the Police National Legal Database?
The PNLD provides legal information and assistance to police forces and other criminal justice organisations. Officers can use the service to obtain guidance on legislation and matters encountered during their duties.
The affected system is therefore a legal information and subscriber database rather than an operational intelligence system containing criminal case files.
PNLD said the database did not contain confidential information about victims, witnesses or offenders.
Members of the public also affected
The incident also affected Ask the Police, a public information service hosted by the PNLD.
PNLD confirmed that some names and email addresses belonging to people who had previously submitted questions through Ask the Police had also been published on the dark web.
The Times reported that approximately 21,000 email addresses belonging to members of the public were included.
Investigation under way
The breach was identified on Sunday 26 July. PNLD said it was working with specialist cybersecurity organisations and the National Crime Agency to investigate the incident and take appropriate action.
Affected organisations were contacted and supplied with information and guidance, while the Information Commissioner's Office was notified.
A cybercriminal group calling itself ExfilSquad has claimed responsibility for the attack. The group reportedly attempted to obtain payment by threatening to publish the information it had taken.
The Guardian reported last week that the attackers claimed to have obtained approximately 135,000 pieces of data from the PNLD. At that stage, only samples were reported to have been posted. The subsequent official PNLD notice confirms that compromised information has now been published on the dark web.
Concerns over officer safety
Although the exposed records do not appear to include home addresses or security credentials, publication of officers' names, workplaces and official email addresses could create risks.
The information could potentially be used for targeted phishing attempts, impersonation, intimidation or efforts to obtain additional confidential material.
Tiff Lynch, chair of the Police Federation of England and Wales, said the reported breach raised serious concerns for the safety of officers and staff. She called for policing and its partners to receive sufficient funding to maintain strong cybersecurity protections.
PNLD said anyone with concerns about the breach could contact it through the dedicated address included in its official notification.