The Police National Legal Database (PNLD) has confirmed that contact details for around 135,000 police officers, criminal justice staff and government partners were stolen and published on the dark web — names, organisations and work email addresses, alongside data from Ask the Police, a public Q&A service hosted on the same platform. PNLD says there’s no evidence passwords or other authentication data were taken, and it has notified the ICO and is working with the National Crime Agency. What makes this one worth a second look, though, isn’t the breach itself — it’s who’s behind it. The extortion group calling itself ExfilSquad, the same crew that claimed responsibility for last week’s Department for Education breach affecting over 600,000 records, currently lists both PNLD and the DfE on its dark web leak site.
Two UK public-sector targets from the same group inside a fortnight isn’t a coincidence, it’s a campaign. And campaigns don’t stop at the target that made headlines — they move to whatever’s next in reach, which increasingly means the suppliers, contractors and smaller organisations that sit in the same digital orbit as a bigger target. Extortion groups like this typically work from whatever access or technique got them in the first time, reusing it against the next target until it stops working, rather than starting from scratch with each new victim.
Why a repeat attacker matters more than a one-off
A single breach is a single failure. A group hitting multiple targets in quick succession, using a repeatable method, tells you something more useful: they’ve found an approach that works, and they’re running it again before defenders catch up. If your business supplies services to, holds contracts with, or exchanges data with any public sector body or larger organisation, it’s worth asking a direct question — would you know if your own systems, or a supplier’s, were the next name added to a leak site like this? Most SMEs find out about this kind of exposure from a customer, a journalist, or the ICO, weeks after the fact, rather than from their own monitoring.
What’s actually worth doing this week
You don’t need to overhaul your security posture in response to a single news story, but two things are worth checking now. First, look at whether your business email addresses, or any contact data tied to your company, are already circulating anywhere they shouldn’t be — dark web monitoring exists precisely to answer that question before a customer does it for you, and KeepSafe is built to flag exactly this kind of exposure early rather than after the damage is done. Second, if you supply services to a public sector body, a school, an NHS trust, or any larger organisation that could plausibly be a future ExfilSquad target, check whether your own access to their systems is protected with multi-factor authentication and a unique password — attackers moving from one victim to the next often go through exactly that kind of supplier connection, not a fresh front-door attack.
If you’re unsure what data your business is legally required to protect, or what you’d need to do if a supplier of yours suffered a breach that touched your data, that’s worth a proper look now rather than after an incident — Smallprint has template guidance covering data protection obligations that’s built for businesses without an in-house legal team. It’s a document worth having ready before an incident forces the question, not drafted under pressure while a leak site is already counting down a payment deadline.
The takeaway
One breach is bad luck. A second one from the same group inside a fortnight is a pattern — and patterns are exactly the kind of thing worth checking your own exposure against, before you find out the hard way.