# U.K. Police Contact Data Is on the Dark Web. The Real Story Is How It Got There.
When law enforcement data lands on a criminal leak site, the narrative usually centers on embarrassment. This story deserves more than that. The breach of the Police National Legal Database isn't just a government agency getting caught with its trousers down — it's a case study in a configuration failure pattern that has burned dozens of organizations this year, almost certainly using the same door.
## Who Got Hit, and What Was Taken
The PNLD provides legal reference services to all 43 Home Office police forces in England and Wales, plus criminal justice partners and government agencies. As of its last annual summary, it supported 108,429 police registrations. That's a lot of people whose professional contact details — names, organizations, work email addresses — are now circulating on the dark web.
The breach was identified July 26, 2026. The threat actor group ExfilSquad claimed PNLD as one of 15 victims on its leak site the same day. PNLD notified the Information Commissioner's Office, engaged the National Crime Agency, and began contacting affected organizations.
Here's where things get murky: as of August 3, PNLD had not disclosed how many individuals were actually affected, when the intrusion began, how long the attacker had access, or how much data was exfiltrated. The breach notice describes the exposed fields without attaching a number to them. That gap matters.
Also caught in the net: people who submitted questions through "Ask the Police," a public-facing service. Named members of the public now have their names and emails associated with police queries, sitting in the same dark web package as officer contact data.
## The Power Platform Problem
This breach did not happen in isolation. VenariX, a threat intelligence firm, reviewed data samples from 11 of ExfilSquad's 15 claimed victims and found Dataverse-consistent structures across all of them. Dataverse is the backend database layer for Microsoft's Power Platform suite — which includes Power Apps and Power Pages.
In the Houston case, VenariX confirmed the mechanism directly: a public portal returning records without authentication, consistent with data published by ExfilSquad. The likely campaign path, per VenariX's assessment, was a Power Pages site with overly permissive "Anonymous Users" access to Dataverse tables, either via Power Pages' Web API or a legacy OData feed.
Microsoft's own documentation is clear on the risk: granting the Anonymous Users role access to a Dataverse table makes its data visible to anyone who can reach the site. No credentials required. The /_api interface inherits whatever permissions are attached to each web role — if Anonymous Users can read a table, so can a threat actor with a browser.
VenariX was careful to note that this attack path hasn't been confirmed for PNLD specifically — no PNLD-specific endpoint, permission setting, or API route has been identified yet. The Power Pages link is a working hypothesis. But when 11 of 15 victims in a single campaign show the same data structures, and the one confirmed case involves exactly this misconfiguration, the hypothesis has weight.
## This Is Not a New Vulnerability. That's the Problem.
The Power Pages anonymous access issue is not a zero-day. Microsoft documented the behavior. The governance control that blocks unauthenticated Dataverse access exists and is configurable. The misconfiguration pattern was publicly flagged in security research as far back as 2022, when a researcher found millions of records exposed from U.S. state governments and private companies through misconfigured Power Apps portals.
That was four years ago.
The PNLD uses Microsoft Power Platform, confirmed by its own annual summary and corroborated by assets on Microsoft's content.powerapps.com domain found in the breach notice page. Whether the specific misconfiguration that VenariX identified in other ExfilSquad victims applies here is unconfirmed. What is confirmed is that the attacker targeted this class of organization, got data consistent with the pattern, and published it.
ExfilSquad appears to be running a systematic campaign against Power Pages deployments with loose anonymous access controls. Fifteen claimed victims in a single campaign is not opportunistic scanning — it's a targeted sweep of organizations that adopted the same platform and didn't lock it down.
## The Phishing Risk Is Understated
PNLD's notice acknowledges that the exposed officer and staff data "could make phishing messages targeting named officers appear more convincing." That framing is polite. Named law enforcement contacts with verified work email addresses are exactly what a social engineering operation needs to manufacture credible pretexts — fake court summons, union communications, internal HR notices, warrant requests.
The Ask the Police exposure compounds this. Members of the public who submitted questions — often about sensitive personal situations — now have their names tied to that activity in a package sitting next to officer contact data. The reputational and personal safety implications for both groups are not minor.
## HackWire Analysis
The PNLD breach fits squarely into what should now be recognized as the Power Platform misconfiguration wave of 2025-2026. Organizations across government and the private sector adopted Microsoft's low-code stack rapidly, often without the security review that enterprise application deployments traditionally receive. Low-code doesn't mean low-risk — it means the security surface moved from custom code to platform configuration, and configuration errors are harder to catch in code review because there's no code to review.
ExfilSquad's campaign is disciplined. Fifteen targets, consistent data structures, a coordinated release cadence on their leak site. This is not a group stumbling onto misconfigured portals by accident. They built or acquired tooling to identify exposed Power Pages deployments at scale — the same kind of automated scanning that ransomware groups use to sweep for unpatched VPNs or exposed RDP.
The opacity from PNLD is frustrating but predictable. Government breach notices chronically understate scope in the initial disclosure period, particularly when investigations are active and victim counts are contested. The ICO notification requirement creates a floor for disclosure, not a ceiling for transparency. Defenders should not wait for PNLD to publish a final accounting before assessing their own exposure.
For any organization running Microsoft Power Pages: VenariX's remediation path is the right starting point regardless of whether you've been hit. Review Anonymous Users table permissions. Audit Web API settings. Check legacy OData feeds. Then validate from an unauthenticated browser session — because that's exactly how ExfilSquad almost certainly validated it first. Microsoft's tenant-level governance control that blocks unauthenticated Dataverse reads is not on by default on every deployment. Find out if it's on for yours.
The question isn't whether more Power Pages victims exist. It's how many organizations in this campaign still don't know they're on the list.
— HackWire Editorial
---
## Related Coverage