Executive Summary
In late July 2026, the ExfilSquad ransomware group claimed responsibility for a cyberattack targeting the U.K.'s Police National Legal Database (PNLD). The attackers allege they exfiltrated approximately 135,000 contact records, including full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. Additionally, data from users of the 'Ask the Police' platform who submitted inquiries were compromised. The PNLD has confirmed the breach and is collaborating with cybersecurity experts and the National Crime Agency (NCA) to investigate the incident. No evidence suggests that passwords or other security credentials were compromised, and the PNLD does not store confidential information related to victims, witnesses, or offenders. (cypro.co.uk)
This incident underscores the persistent threat posed by ransomware groups like ExfilSquad, who continue to target public sector entities. The breach highlights the critical need for robust cybersecurity measures, including multi-factor authentication and continuous monitoring, to protect sensitive information and maintain public trust.
Why This Matters Now
The ExfilSquad attack on the PNLD highlights the escalating threat of ransomware groups targeting public sector entities, emphasizing the urgent need for enhanced cybersecurity measures to protect sensitive data and maintain public trust.
Attack Path Analysis
The ExfilSquad group gained unauthorized access to the Police National Legal Database (PNLD) by exploiting a public-facing application vulnerability. They escalated privileges to access sensitive data, moved laterally within the network to locate and collect over 100,000 contact records, established command and control channels to exfiltrate the data to their own cloud storage, and ultimately leaked the information, impacting the privacy of police officers and staff.
Kill Chain Progression
Initial Compromise
Description
ExfilSquad exploited a vulnerability in a public-facing application to gain unauthorized access to the PNLD.
MITRE ATT&CK® Techniques
Valid Accounts
Phishing
Application Layer Protocol
Exfiltration Over C2 Channel
Inhibit System Recovery
Data Encrypted for Impact
File and Directory Discovery
Command and Scripting Interpreter
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
ISO/IEC 27001 – Event Logging
Control ID: A.12.4.1
CISA Zero Trust Maturity Model 2.0 – Identity Governance
Control ID: Identity Pillar
DORA – ICT Risk Management Framework
Control ID: Article 5
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Enforcement
Primary target sector with 100,000+ officer records compromised via data extortion, requiring enhanced egress security and encrypted traffic protection capabilities.
Government Administration
High-risk exposure through criminal justice partnerships and shared databases, necessitating zero trust segmentation and multicloud visibility for data protection.
Information Technology/IT
Critical infrastructure vulnerability demonstrated by PNLD breach, requiring threat detection, anomaly response, and cloud firewall capabilities for service providers.
Legal Services
Significant exposure through legal database access and criminal justice professional data compromise, demanding enhanced egress filtering and policy enforcement.
Sources
- ExfilSquad hackers leak info of over 100,000 UK police officers, staffhttps://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/Verified
- Dark Web Profile: ExfilSquadhttps://socradar.io/blog/dark-web-profile-exfilsquad/Verified
- NVD - Homehttps://nvd.nist.gov/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised application, reducing the likelihood of further unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained, limiting access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been restricted, reducing the scope of data they could access.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could have been detected and disrupted.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been blocked, preventing data loss.
The overall impact of the breach could have been minimized, reducing the exposure of sensitive information.
Impact at a Glance
Affected Business Functions
- Legal Resource Services
- Public Inquiry Management
- Law Enforcement Communication
Estimated downtime: N/A
Estimated loss: N/A
Full names, organizations, and email addresses of police officers, staff, criminal justice professionals, government partners, and users who submitted questions through the 'Ask the Police' platform.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy East-West Traffic Security to monitor and control internal traffic flows.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities.
- • Regularly update and patch public-facing applications to mitigate known vulnerabilities.



