Back to all lessons
Awareness Lessons
2 months ago

ExfilSquad Leaks 100,000+ UK Police Records in PNLD Breach

The Police National Legal Database breach exposed personally identifiable information of over 100,000 law enforcement and criminal justice professionals, highlighting the severe risk of centralised databases holding sensitive personnel data without adequate protective controls. The fact that a single extortion group could exfiltrate 1.9 GB of subscriber records suggests insufficient data access controls, inadequate monitoring of bulk data movement, and potentially weak segmentation around a high-value target. While no passwords or victim/witness data were reportedly compromised, the exposure of officer names, organisations, and email addresses creates significant risks for targeted phishing, social engineering, and physical safety threats against named officers. Organisations holding sensitive professional directories must treat personnel contact databases with the same rigour as classified operational data.

Tactical Insight

Immediate actions

  • Audit and restrict access to subscriber and personnel databases using role-based access control, limiting bulk query and export capabilities.
  • Force a credential reset and implement multi-factor authentication for all PNLD and associated portal accounts as a precautionary measure.
  • Notify all 100,000+ affected individuals promptly and provide guidance on recognising phishing attempts targeting their exposed details.

Detection & Monitoring measures

  • Deploy Data Loss Prevention (DLP) tools to detect and alert on anomalous bulk data exports or large-volume query activity against personnel databases.
  • Implement User and Entity Behaviour Analytics (UEBA) to flag unusual access patterns, especially after-hours or high-volume record retrieval.
  • Ensure SIEM logging captures all database access events with sufficient retention to support forensic investigation.

Long-term improvements

  • Apply the principle of data minimisation — store only the fields strictly necessary for each user role and avoid aggregating sensitive directories in a single accessible database.
  • Conduct regular third-party penetration testing and threat modelling specifically against databases holding law enforcement personnel data.
  • Establish a formal data extortion response playbook, including pre-agreed legal, communications, and law enforcement escalation procedures.