ExfilSquad Leaks Contact Details of 100,000+ UK Police Officers and Staff
What Happened – Hackers from the ExfilSquad extortion group breached the Police National Legal Database (PNLD), extracting roughly 135,000 contact records that include full names, organisations and email addresses of police officers, criminal‑justice staff and users of the public “Ask the Police” portal. The breach was discovered on 26 July 2026 and the group has published sample data while demanding a ransom.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook case of a data‑exposure breach that SOC 2 privacy and security criteria (CC5 Privacy, CC6 Security) are designed to mitigate and document.
- Continuous evidence of access‑control monitoring, data‑handling policies and incident‑response testing is required to demonstrate due diligence to regulators (ICO) and auditors.
- Verisq’s CookiePLUS privacy capability provides the audit‑ready consent, DSAR handling and data‑mapping evidence needed to close the gap exposed by this breach.
Who Is Affected – Public‑sector law‑enforcement agencies (Home Office police forces, British Transport Police) and any external partners whose contact details reside in PNLD.
Recommended Actions
- Map the exposed personal data to SOC 2 CC5 controls; verify that consent, purpose limitation and data‑retention policies are documented and enforceable.
- Capture forensic logs and evidence of the detection timeline as audit artifacts; update your incident‑response playbook to include public‑facing data‑extortion scenarios.
- Conduct a privacy‑impact assessment (PIA) and ensure DSAR processes are ready for potential subject‑access requests from affected individuals.
Technical Notes – The breach vector has not been disclosed; no password or credential compromise was reported. The stolen dataset totals ~1.9 GB and comprises 114 k PNLD subscriber records plus 21 k “Ask the Police” user records. Source: BleepingComputer