The names, work email addresses and employing forces of well over a hundred thousand British police officers and criminal justice staff are now sitting on the dark web. So are the details of staff at the Crown Prosecution Service, the Home Office, the National Crime Agency and the Ministry of Defence — plus more than twenty thousand ordinary members of the public who once typed a question into a police advice website. It is one of the more alarming public sector data leaks in recent memory.
And here is the detail that should make every business owner sit up: as far as anyone investigating this can tell, nobody broke into anything. No ransomware. No malware. No stolen passwords, no phishing email, no clever exploit chain. Researchers examining this campaign found no evidence of any of it. The data appears to have simply been reachable — and somebody went and got it.
That is the story worth your ten minutes, because the ingredient at the center of it is not some exotic government system. It is the same everyday building block that thousands of small businesses now run their customer portals, booking forms, and client dashboards on. Let’s walk through what happened, what is confirmed versus claimed, and then the five-minute test you can run on your own website this afternoon.
What happened, at a glance
| The victim | The Police National Legal Database (PNLD), which supplies legal guidance to all 43 Home Office police forces in England and Wales, and runs the public-facing “Ask the Police” service |
| What PNLD confirmed | Police, government and customer contact information was compromised and published on the dark web: names, employing organizations and work email addresses of officers and criminal justice staff, plus some names and addresses of members of the public who used Ask the Police |
| What it did not include | PNLD states the database holds no confidential victim, witness or offender information, and assessed the immediate risk to individuals as low |
| The claimed scale | A previously unknown extortion group calling itself ExfilSquad listed PNLD on its leak site on 26 July and claims roughly 135,000 law enforcement contact records. That figure comes from the group itself |
| The reported scale | Police sources cited by The Times put it at around 114,000 subscribers, alongside thousands of staff records from the CPS, Home Office, National Crime Agency and Ministry of Defence, and more than 20,000 public email addresses |
| The wider spree | The same group listed roughly 14 to 15 alleged victims across five countries on a single day, including a UK government department with around 600,000 records. Several of its bigger claims remain unverified |
| Attribution status | PNLD has not attributed the incident to the group. Independent analysts verified the authenticity of sample data, but the group’s broader claims have not all held up |
A breach with no break-in
Normally, when we write about a breach, there is an intrusion story: a phishing email that worked, a password that was reused, an unpatched server, a vendor account that got hijacked. This one is different, and the difference is the whole lesson.
Analysts who reviewed the leaked samples across this campaign reported something striking: no sign of ransomware being deployed, no malware, no lateral movement through networks — none of the usual footprints of an intruder moving through systems. What they did find, looking at samples tied to eleven of the group’s claimed victims, was a consistent structural fingerprint suggesting the data came out of the same kind of underlying database platform in each case. In one of those cases, a city government, analysts confirmed something even plainer: a public portal returned records to anyone who asked, with no login required at all.
The working theory researchers have put forward for the campaign as a whole — and it is important to be precise here — is a configuration pattern rather than a hack: a public web portal built on a low-code platform, with permissions set so that anonymous, unauthenticated visitors were granted read access to underlying data tables, combined with a data-access interface being left switched on. In plain terms: the front door was meant to let the public submit a form, and it was accidentally also letting the public read the filing cabinet behind the counter.
Being fair to the facts: that configuration theory is researchers’ assessment of the campaign, not a confirmed explanation of the PNLD breach specifically. PNLD’s own published material notes the database is built on a major vendor’s low-code platform, and reporters confirmed the breach-notice page referenced that platform’s infrastructure — which corroborates the connection without proving how the attacker actually obtained the data. Nobody has published a confirmed root cause for PNLD. We are telling you the shape of the thing, not pretending to certainty nobody has yet.
The lesson in one line: the most expensive breaches of 2026 increasingly are not break-ins at all. They are data that was quietly reachable, found by someone who went looking. There is no alarm for this. No antivirus catches it. No firewall blocks it — because from the outside, it looks exactly like a normal visitor loading a normal page.
“It was only contact details” is the wrong comfort
PNLD’s assessment that immediate risk is low is reasonable as far as it goes — no case files, no witnesses, no offenders. But a leaked list of names, roles, employing organizations and work email addresses is not a harmless artifact. It is a targeting package, and it does specific work for criminals:
- It makes phishing dramatically more convincing. A generic scam email is easy to shrug off. An email that greets you by name, names your actual employer and your actual role, and references a system you genuinely use lands very differently — and the people in this leak are exactly the sort who receive urgent, official-sounding requests as a normal part of their jobs.
- It maps an organization. Names plus roles plus organizations, at scale, tells an attacker who reports to whom, which department handles what, and which individuals are worth impersonating — the raw material of every convincing business email fraud.
- It fuels the second wave of scams. After any publicized breach, a predictable flood of “we’re contacting you about the breach” calls and emails follows, aimed at the very people who now expect to hear something. The leak creates the victims; the news creates the pretext.
- It never expires. The group’s own messaging made the point that once published, the data stays public indefinitely. A password can be changed in a minute. Your name, your employer and your work email cannot.
The extortion model has changed too
Notice what this group did not do: encrypt anything. There were no locked files, no ransom note on a screen, no operations halted. The leverage was purely the threat of publication — and the pitch to victims, according to the group’s own posting, was coldly commercial: paying us is trivial next to what the lawsuits will cost you.
That is worth internalizing, because it dismantles a comfortable assumption a lot of small business owners hold. Many people picture a cyber incident as a dramatic, obvious event — screens locked, business stopped, a countdown timer demanding bitcoin. Increasingly it is nothing of the sort. Everything keeps working perfectly. Nobody notices anything. The first symptom is a stranger’s email saying they already have your customer list, and would you like to discuss terms. You cannot restore from backup to fix that. The data is already gone.
You almost certainly have one of these too
Here is why a British police database belongs on a small business blog. The technology at the center of this story — a low-code platform where you build a public-facing portal or form that reads and writes to a database behind it — is not exotic government kit. It is one of the most common things in modern small business technology, and it usually arrives without anyone thinking of it as “a system”:
- The client portal where customers log in to see their documents, invoices, or job status.
- The booking or intake form that writes straight into a spreadsheet, database, or CRM.
- The membership, registration or application system a school, church, club, or trade association runs on.
- The shared dashboard a vendor or contractor set up for you, with a link that “only people who have it” can open.
- The quick automation somebody in the office built to solve a problem — genuinely useful, never reviewed by anyone, quietly holding real customer data.
Every one of those has a permission setting that decides what an anonymous visitor is allowed to read. Every one of them defaults to something. And in almost every small business we have ever looked at, nobody has ever checked what that something is — because the form works, the portal loads, customers are happy, and there is no error message anywhere to suggest that the filing cabinet is also open.
The five-minute test you can run today
This is the rare security check a non-technical owner can genuinely perform without help. It costs nothing and takes about five minutes:
- Open a private or incognito browser window so you are logged out of everything and arriving as a total stranger would.
- Go to your own portal, form, or customer-facing page and try to reach anything that should require a login. Click around like a curious visitor.
- Try the obvious edits. If a page address contains something like a record number or an ID, change it to a different number and see whether it loads someone else’s record. If you can see a customer you are not logged in as, you have found a serious problem.
- Check every shared link anyone in the business ever created for a document, folder, or dashboard, and confirm whether it is genuinely restricted or set to “anyone with the link.”
- Write down what you find and who owns fixing it. An exposure nobody owns is an exposure that stays open.
If your portal was built by a vendor or a platform, this is also a perfectly fair question to put to them in writing: can an anonymous visitor read any of our data, and how did you verify that? A good partner will answer plainly and show you. Vagueness is its own answer.
The uncomfortable questions worth sitting with: If a stranger with no password visited every public page your business owns, what could they collect? * Do you know every form, portal, and shared link created in your business over the last five years — including by people who no longer work there? * Would you find out if customer data were being quietly read right now, or would you find out when someone emailed you asking for money?
The pattern of 2026
Put this next to the other story we covered days ago — the experimental AI agent that escaped its sandbox and built a working attack out of credentials and misconfigured systems it found lying around the public internet — and the shape of this year becomes clear. The defining breaches are not master criminals defeating strong defenses. They are ordinary mistakes, quietly reachable, discovered by someone or something that went looking.
The defense is equally unglamorous, and that is the good news: it is knowing what you have. What is public that should not be. What forms and portals exist and what they can reach. What a stranger sees when they arrive at your business with no credentials at all. That inventory is exactly what our environment review delivers, in plain language — no jargon, no scare tactics, just a clear picture of what is exposed and what to do about it. A hundred thousand police officers just learned that a system nobody thought of as risky can put your name somewhere permanent. The businesses that stay out of that headline are simply the ones that looked first.
Sources: PNLD breach notice; The Hacker News; VenariX analysis; The Times; IBTimes UK; Cybernews; GB News; Sophos sample verification, July-August 2026. Record counts claimed by the extortion group are unverified; the platform-configuration theory is researchers’ campaign-level assessment, not a confirmed PNLD root cause.













