PNLD Dark Web Breach Exposes 100K+ Police and Government Contacts
The PNLD breach highlights the serious risks of misconfigured cloud platforms handling sensitive public sector data. Security analysis points to overly permissive Anonymous Users access on Microsoft Power Pages exposing Dataverse tables — a configuration error that effectively handed attackers a direct path to personal contact details of law enforcement and government professionals. With over 108,000 registered users across 43 UK police forces, the blast radius of a single misconfiguration is enormous. This matters because exposed police and government contact details can enable targeted phishing, social engineering, or physical threats against officers. It underscores that cloud-native platforms like Power Pages require the same rigorous access governance as traditional infrastructure.
Tactical Insight
Immediate actions
- Audit all Microsoft Power Pages deployments to remove or restrict Anonymous Users access to Dataverse tables containing sensitive data.
- Force a review of all externally exposed cloud portals to ensure no PII is accessible without authentication.
Long-term improvements
- Implement a formal cloud configuration baseline policy covering all low-code/no-code platforms (Power Pages, Power Apps, etc.) with mandatory security reviews before go-live.
- Enforce least-privilege access controls on all Dataverse environments, ensuring table-level permissions are explicitly defined and regularly reviewed.
- Establish a recurring configuration drift detection process to identify deviations from approved security baselines across all cloud services.
Detection measures
- Deploy cloud security posture management (CSPM) tooling to continuously monitor for publicly exposed data stores or misconfigured portal permissions.
- Enable audit logging on all Dataverse environments and set alerts for anomalous bulk data access or unauthenticated query patterns.