top of page
Scheider_300x600.jpeg
nvidio_728x90.png
TechNewsHub_Strip_v1.jpg

LATEST NEWS

ExfilSquad hackers dump contact details of 100,000 UK police officers and staff online

  • Marijan Hassan - Tech Journalist
  • 2 hours ago
  • 2 min read

A cyber extortion campaign targeting UK law enforcement and government bodies has escalated after the threat actor group ExfilSquad leaked a massive contact directory containing personal details of over 100,000 police officers, force staff, and criminal justice workers.



The breach centers on the Police National Legal Database (PNLD), an online legal information resource hosted by West Yorkshire Police and utilized by Home Office forces across England and Wales.


Scope of the Exfiltrated Directory

Forensic teams confirmed that ExfilSquad exfiltrated approximately 1.9 GB of data totaling around 135,000 individual records. The hackers published sample files and bulk datasets to their dark web leak site after failed extortion attempt.


According to notifications from the PNLD and national investigators, the compromised data includes:

  • Serving Personnel: Full legal names, force affiliations, job titles, and official work email addresses for over 100,000 police officers and administrative staff.

  • Partner Entities: Contact details for criminal justice professionals, university administrators, and government agency personnel with active accounts.

  • Public Inquiries: Names and email addresses submitted by members of the public using the associated "Ask the Police" online advisory service.


Authorities reiterated that no site passwords, financial accounts, or sensitive operational case files were compromised in the intrusion.


Physical Security and Phishing Escalation

Despite the lack of exposed password hashes, the release of verified names and organizational links presents severe security concerns. Police representatives and former undercover officers voiced alarm that publicly linking personnel names to specialized police units, such as serious organized crime, counter-terrorism, or surveillance teams, creates severe personal safety risks for officers who have spent years maintaining operational anonymity.


Cybersecurity analysts further warn that the leaked directory serves as an immediate blueprint for social engineering. Attackers can use the accurate combination of names, email addresses, and departmental roles to deploy targeted spear-phishing campaigns, credential harvest attacks, and impersonation schemes against UK law enforcement infrastructure.


Multi-Agency Security Investigation

The National Crime Agency (NCA) and the National Cyber Security Centre (NCSC) have launched a joint forensic investigation alongside the UK Information Commissioner's Office (ICO). The PNLD breach forms part of a broader wave of extortion attacks linked to ExfilSquad targeting UK public institutions, following a similar compromise of customer help-desk portals at the Department for Education days earlier.


Authorities are advising all law enforcement agencies to implement heightened email monitoring, enforce strict multi-factor authentication, and monitor for targeted credential-phishing attempts using the leaked contact lists.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page