The Police National Legal Database confirmed that contact details for police officers, government partners, and customers were stolen and posted on the dark web. The service, which supplies legal information and products to UK police forces and criminal justice organisations, disclosed the incident on July 26. The compromised information included names, organisations, and work email addresses for police officers, police staff, criminal justice professionals, government partners, and customers, according to The Hacker News report published August 3, 2026.
The breach also revealed names and email addresses for some individuals who had asked questions through Ask the Police. PNLD stated there's no evidence passwords or other security credentials were taken. As of August 3, the organisation hasn't publicly disclosed how many people were affected, when the intrusion started, how long attackers maintained access, or the total volume of stolen information. PNLD reported 108,429 police registrations and support for all 43 Home Office police forces in its 2025-26 annual summary, though that figure represents total users, not breach victims. The service notified the Information Commissioner's Office and is collaborating with the National Crime Agency and specialist cybersecurity organisations.
The report states that UK government guidance warns the exposure could make phishing messages targeting named officers seem more convincing. PNLD emphasised it isn't the Police National Computer or Police National Database, doesn't function as a crime-recording system, and holds no confidential details about victims, witnesses, or offenders. The organisation contacted all affected organisations and gave them additional information and guidance, while affected Ask the Police users received an email with further details.
VenariX examined samples tied to 11 of ExfilSquad's 15 claimed victims and discovered Dataverse-consistent structures across all 11 cases. In Houston's case specifically, the cybersecurity firm confirmed a public portal returned records without requiring authentication and those records matched data the group published. VenariX assessed the probable campaign-level pathway as a public Power Pages site with broad Anonymous Users access to Dataverse tables, which also required an enabled Power Pages Web API or legacy OData feed. Microsoft's documentation notes that granting the Anonymous Users role access to a table makes its data visible to anyone visiting the site, while its Web API documentation explains the interface follows table permissions attached to each web role. The Hacker News verified on August 3 that the breach-notice page referenced assets hosted on Microsoft's content.powerapps.com domain, which supports the platform connection but doesn't show how attackers obtained the data.
VenariX said the evidence "does not yet confirm that every organization was affected through an exposed Power Apps portal or the same configuration issue." At this stage, the Power Pages link remains a hypothesis requiring testing rather than a confirmed explanation of the PNLD breach, since neither PNLD's notice nor VenariX's report identified a PNLD-specific endpoint, permission setting, API route, or supporting log. ExfilSquad listed PNLD on its leak site on July 26, but PNLD hasn't attributed the incident to the group. VenariX found no evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability in the campaign material it reviewed.
Microsoft provides a tenant-level governance control that blocks unauthenticated users from reading Dataverse data while still permitting public form submissions. VenariX recommends that Power Pages operators review Anonymous Users table permissions, Web API settings, and legacy OData feeds, then validate access from an unauthenticated browser session. Those measures address the configuration pattern VenariX identified, not a confirmed PNLD root cause, but they offer a practical path to prevent similar exposures until organisations can verify their exact security posture.

