UK Police Legal Database Allegedly Breached in 135K Record Leak

A threat actor claims to have stolen 135,000 contact records from the Police National Legal Database including police emails and portal metadata.
Forum post claiming a breach of the UK Police National Legal Database and the theft of 135,000 law enforcement contact records.
Forum post in which a threat actor claims to have breached the UK Police National Legal Database (PNLD) and stolen approximately 135,000 law enforcement contact records. The claim has not been independently verified.

A threat actor claims to have breached the Police National Legal Database and obtained approximately 135,000 contact records connected to law enforcement personnel and other authorized users across the United Kingdom.

The alleged dataset reportedly contains names, police and organizational email addresses, force affiliations, portal account details, login timestamps, authentication settings, and internal system identifiers.

The claim remains unconfirmed. The Police National Legal Database and West Yorkshire Police had not issued any public statement addressing the alleged breach at time of publication.

Claim targets a national criminal law resource

The Police National Legal Database, commonly known as PNLD, is an online criminal law resource governed by West Yorkshire Police and used throughout the criminal justice system in England and Wales.

The service provides legislation, case summaries, legal guidance, national standard offence wording, and offence codes used by police forces and other public-sector organizations.

All 43 Home Office police forces in England and Wales rely on the platform. Other users include the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct, and His Majesty’s Courts and Tribunals Service.

The threat actor alleges that 135,000 contact records were extracted from PNLD. No information was provided about when the alleged intrusion occurred, how access was obtained, or whether the actor continues to have access to the affected environment.

Sample resembles portal account data

A sample published with the claim appears to contain a detailed contact record exported from a Microsoft Dynamics or Dataverse environment. BreachNews is not reproducing the sample because it contains identifiable information belonging to a law enforcement user.

The fields visible in the sample reportedly include:

  • First and last names
  • Law enforcement and organizational email addresses
  • Associated police force or agency
  • Portal usernames and contact identifiers
  • Account status and login settings
  • Last successful login timestamps
  • Authentication and access classifications
  • Communication and subscription preferences
  • Internal Microsoft Dynamics system metadata

The sample also contains fields related to identity security stamps, account lockout controls, email confirmation status, and two-factor authentication settings. These values could provide attackers with useful context for targeted phishing or account takeover attempts even when they do not include usable passwords.

Password hash and temporary password fields appeared empty in the public sample. There is currently no evidence that plaintext passwords or working password hashes were exposed.

No indication criminal records were included

Despite its name, PNLD is different from the Police National Computer and the Police National Database. It primarily provides criminal law and legal reference material rather than serving as the national repository for arrest histories, intelligence reports, vehicle records, or criminal case evidence.

The information shown in the alleged sample appears to relate to PNLD subscribers and portal users. Nothing disclosed publicly indicates that criminal records, active investigation files, intelligence reports, witness statements, or evidentiary material were obtained.

The threat actor described the collection as law enforcement contact data. The full dataset has not been independently examined, and it remains unclear whether all 135,000 records represent active police personnel, former users, duplicate entries, external subscribers, or contacts associated with other criminal justice organizations.

Police identities could support targeted attacks

If authentic, the combination of names, official email addresses, police force affiliations, and account activity information could support convincing phishing and impersonation campaigns.

An attacker could use accurate organizational details to pose as PNLD support staff, another police force, Microsoft, or an internal technology administrator. Messages could be designed to capture credentials, authentication codes, or access to other law enforcement services.

The exposure of last-login dates and account status fields could also help attackers prioritize active users. Internal identifiers and platform metadata may provide additional information about how the portal is structured, although those values do not necessarily provide direct access by themselves.

Scope and access method remain unanswered

The forum account behind the claim has little publicly visible history and did not provide technical evidence explaining how PNLD was allegedly compromised. The post included a sample record and directed readers to an external leak site, but BreachNews has not accessed or downloaded the purported dataset.

PNLD has not confirmed whether its systems were accessed or whether any user information was exposed. It is also unclear whether West Yorkshire Police, the Information Commissioner’s Office, or the National Cyber Security Centre is investigating the allegation.

Organizations with PNLD accounts should remain alert for unexpected login prompts and messages referencing the service. Users should verify requests through established internal channels and avoid providing passwords or authentication codes in response to unsolicited communications.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site