Executive Summary
In late July 2026, the Police National Legal Database (PNLD) identified a data breach resulting in the exposure of contact information for police officers, government partners, and customers. The compromised data, which included names, organizations, and work email addresses, was subsequently published on the dark web. PNLD has stated that there is no evidence to suggest that passwords or other security credentials were compromised. The organization has notified affected parties and is collaborating with the Information Commissioner's Office (ICO) and the National Crime Agency (NCA) to investigate the incident.
This breach underscores the growing trend of cyberattacks targeting public sector organizations and the critical importance of securing sensitive contact information. The incident highlights the need for robust data protection measures and proactive monitoring to prevent unauthorized access and data exposure.
Why This Matters Now
The PNLD breach highlights the increasing frequency of cyberattacks on public sector entities, emphasizing the urgent need for enhanced cybersecurity measures to protect sensitive information and maintain public trust.
Attack Path Analysis
The attacker exploited misconfigured anonymous access settings in PNLD's Microsoft Power Pages portal to access sensitive contact information. No evidence suggests the attacker escalated privileges beyond the initial access. The attacker did not move laterally within the network, focusing solely on the exposed data. There is no indication of command and control activities, as the attack was limited to data access. The attacker exfiltrated the contact information and published it on the dark web. The impact includes potential phishing attacks targeting the exposed individuals.
Kill Chain Progression
Initial Compromise
Description
Exploited misconfigured anonymous access in Microsoft Power Pages portal to access sensitive data.
MITRE ATT&CK® Techniques
Valid Accounts
Data from Cloud Storage
Exfiltration Over Web Service
Acquire Infrastructure: Domains
Establish Accounts: Social Media Accounts
Compromise Accounts: Social Media Accounts
Develop Capabilities: Malware
Obtain Capabilities: Malware
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Account Management
Control ID: AC-2
PCI DSS 4.0 – Limit Access to System Components and Cardholder Data
Control ID: 7.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Enforcement
Direct impact from PNLD breach exposing police officer contact details on dark web, enabling targeted phishing attacks against law enforcement personnel.
Government Administration
Government partner contact information compromised in data breach, creating security risks for public sector operations and inter-agency communications.
Information Technology/IT
Microsoft Power Platform misconfiguration highlights cloud security vulnerabilities, requiring enhanced egress controls and zero trust segmentation for IT infrastructure.
Computer/Network Security
Cybersecurity organizations involved in incident response face exposure risks while demonstrating need for improved multicloud visibility and threat detection capabilities.
Sources
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Webhttps://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.htmlVerified
- Data breaches: guidance for individuals and familieshttps://www.ncsc.gov.uk/guidance/data-breachesVerified
- VenariX Analysis of ExfilSquad's Exploitation of Microsoft Power Pageshttps://venarix.com/blog/exfilsquad-targets-misconfigured-microsoft-power-pages-portalsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit misconfigured access settings, thereby reducing the scope of data exposure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured access settings would likely have been constrained, reducing the scope of data exposure.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been constrained, maintaining the integrity of the system.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely have been constrained, reducing the risk of further data exposure.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely have been constrained, reducing the risk of persistent threats.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely have been constrained, reducing the risk of data leakage.
The potential for phishing attacks targeting exposed individuals would likely have been reduced, mitigating the overall impact.
Impact at a Glance
Affected Business Functions
- Legal Information Services
- Customer Support
- Public Inquiry Handling
Estimated downtime: N/A
Estimated loss: N/A
Names, organizations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and customers; names and email addresses of individuals who submitted inquiries through 'Ask the Police'.
Recommended Actions
Key Takeaways & Next Steps
- • Review and correct anonymous access settings in Microsoft Power Pages portals to prevent unauthorized data exposure.
- • Implement Zero Trust Segmentation to enforce least privilege access and minimize potential attack surfaces.
- • Utilize Multicloud Visibility & Control to monitor and manage access permissions across cloud environments.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unauthorized access attempts promptly.
- • Conduct regular security audits and penetration testing to identify and remediate misconfigurations and vulnerabilities.



