In a major cybersecurity incident reported on August 3, 2026, the Police National Legal Database (PNLD)—a key legal information platform used across all 43 UK Home Office police forces and criminal justice organizations—confirmed that contact details and work credentials belonging to law enforcement personnel and public sector partners were breached and leaked on the dark web.

Unpacking the Incident and Exposure Scope

The compromised dataset includes full names, official organization titles, and work email addresses of police officers, legal staff, criminal justice professionals, and citizens who submitted inquiries through public inquiry portals. Threat intelligence researchers investigating the breach noted that the exposed records stem from cloud-hosted portal assets using Microsoft Power Platform technologies.

Although law enforcement officials confirmed that passwords and core criminal justice databases were not compromised, the leak of verified contact rosters creates significant social engineering risks. Cybercriminals can leverage these exposed directories to launch highly targeted spear-phishing and voice phishing (vishing) campaigns against public sector employees.

Key Cloud Security Governance Takeaways

Security analysts investigating campaign-level patterns in low-code cloud environments highlight several critical access control measures:

  • Audit Anonymous Access Roles: Audit public cloud portals (such as Power Pages or Dataverse environments) to ensure anonymous user roles do not grant unauthenticated read privileges to internal data tables.
  • Restrict API Endpoints: Disable public OData and Web API interfaces on administrative tables unless explicit authentication is required.
  • Implement Continuous Phishing Protections: Enforce multi-factor authentication (MFA) and continuous behavioral monitoring for all official accounts exposed in public data leaks.

Source: The Hacker News