PNLD: 135,000 police and partner contacts published on the dark web
The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.
On August 4, 2026, the Police National Legal Database (PNLD), a criminal law database used by the 43 police forces of England and Wales, confirmed that a data theft over the July 26–27, 2026 weekend led to the publication on the dark web of users’ professional contact details. Exposed data includes names, organizations, and email addresses of police personnel, other criminal justice professionals, government partners, and people who submitted questions via the “Ask the Police” website. The ExfilSquad group claimed the attack and says it released 1.9 GB of data covering 114,000 PNLD subscribers and 21,000 Ask the Police users. PNLD notified the ICO and the National Crime Agency, and says there is no evidence of compromised passwords. These confirmations were reported by ITPro and TechRadar.
Legal framework and basis
In the UK, personal data processing is governed by the UK GDPR and the Data Protection Act 2018. Relevant obligations here include security of processing (equivalent to Article 32 of the GDPR) and prompt notification to the supervisory authority (equivalent to Art. 33). For Luxembourg readers, the parallel is direct: Article 32 requires risk‑appropriate security; Articles 33 and 34 require notification to the CNPD within 72 hours and, where applicable, information to data subjects. By analogy, governance and notification duties under the NIS 2 directive apply to authorities, essential/important entities, and their providers.
The public timeline (detected July 26, 2026; publication confirmed August 4, 2026) and data nature (large sets of professional contacts) fit a trend of exfiltration attacks against operational directories, with downstream phishing and spearphishing impacts.
What this means for Luxembourg organizations
- Priority risk: exposure of named email directories and job roles fuels highly credible spearphishing against executives, finance, procurement, IT, and regulators, enabling CEO fraud, IBAN changes, or MFA fatigue attacks.
- Sector exposure: NIS 2 entities, PSFs, DORA‑regulated financial institutions and their vendors hold similar registers (clients, agents, suppliers, regulator contacts), engaging GDPR, NIS 2 and, for finance, DORA obligations.
- Timing and evidence: upon suspected exfiltration, provable timelines and evidence of controls (segmentation, DLP, hardened SaaS, mail security) become critical with supervisory authorities.
Immediate actions to take this week
- Inventory and secure exposed “directories”: CRM exports, mailing lists, support portals, partner/supplier bases; enforce encryption at rest, role‑based access control, and remove default external shares.
- Harden email and SaaS: DMARC reject, SPF, DKIM; stronger authentication (FIDO2/WebAuthn) for admin consoles; DLP in M365/Google Workspace for named emails and sensitive roles.
- Reduce portal attack surface: WAF/WAAP with file inspection and anomaly detection, reCAPTCHA/antibot, “impossible travel” policies, detailed export logging and alerts on bulk extractions.
- Boost 24/7 spearphishing detection: SOC playbooks for directory leaks (IOCs, VIP alerts, token resets), targeted simulations for finance/procurement/IT, and out‑of‑band verification of payments and banking changes.
- Prepare the notification triad: GDPR (Art. 33) drafts, NIS 2 preliminary alert (within 24h), and DORA (for financial entities), with objective “high risk” criteria (Art. 34) and communication scripts.
Go further
To track and detect releases of stolen datasets affecting your domains and identities, consider integrated dark web monitoring within your incident response procedures and SOC.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →