Find notable cyber news and cases, enriched with sources, timelines, and signals.

Police National Legal Database (PNLD) hit by network compromise

Incident
First reported
Last updated
Happening score
H score 45
3 unique sources, 3 articles

Summary

Hide ▲

The Police National Legal Database (PNLD) suffered a data security incident that exposed names, organizations, and work email addresses for police officers, police staff, criminal justice professionals, government partners, and customers, with the data later published on the dark web. PNLD said the issue was identified on July 26 and that there was no evidence passwords or other security credentials were compromised. The incident also affected Ask the Police, where some names and email addresses from prior question submissions were exposed. The extortion group ExfilSquad claimed responsibility and said it held 1.9GB of data and 135,000 records.

Related Happenings

Police National Legal Database dark-web contact data leak

Data Leak
H score34 First: 03.08.2026 12:13 Last: 03.08.2026 12:13 Sources 1

How related: The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.

About this happening: The Police National Legal Database (PNLD) confirmed that contact information for police, government and customer users was published on the dark web, exposing names an...

NCA charges five in Russian Coms cybercrime case

Law Enforcement
H score35 First: 13.07.2026 16:23 Last: 13.07.2026 16:23 Sources 1

About this happening: UK authorities charged five people in the Russian Coms scam-call case, escalating a cybercrime prosecution tied to caller ID spoofing and over 1.8 million scam calls...

Peter Stokes extradited and charged in Scattered Spider cybercrime case

Law Enforcement
H score57 First: 02.07.2026 11:45 Last: 02.07.2026 11:45 Sources 1

About this happening: The US Justice Department arrested and extradited Peter Stokes in a cybercrime case, bringing an alleged Scattered Spider member into US custody for prosecution. H...

Charter Communications hit by network compromise linked to ShinyHunters

Incident
H score70 First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...

Latest development: 29.05.2026 11:29

Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.

Finnish arrest and U.S. charges in Bouquet Scattered Spider case

Law Enforcement
H score45 First: 28.04.2026 18:39 Last: 28.04.2026 18:39 Sources 1

About this happening: Finnish law enforcement arrested Bouquet, and U.S. federal prosecutors later charged him in a cross-border Scattered Spider cybercrime case. The charges include ...

Timeline

  1. 03.08.2026 12:13 3 articles · 4d ago

    ExfilSquad lists PNLD contact data on leak site

    Attribution Update

    On July 26, ExfilSquad listed the Police National Legal Database (PNLD) on its leak site, and some names and email addresses belonging to people who had submitted questions through Ask the Police were also exposed. The exposed personal details could make phishing messages targeting named officers appear more convincing.

    Show sources
  2. 03.08.2026 12:13 2 articles · 4d ago

    PNLD confirms police and government contact data was published on the dark web

    Initial Disclosure

    As of August 3, 2026, PNLD confirmed that police, government and customer contact information was compromised and published on the dark web, including names, organisations and work email addresses for police officers, police staff, criminal justice professionals, government partners and customers. PNLD said there was no evidence that passwords or other security credentials had been compromised, notified the Information Commissioner's Office (ICO), and said it was working with the National Crime Agency (NCA) and specialist cybersecurity organisations.

    Show sources