ExfilSquad Ransomware Claims Police Legal Database Leak

Unverified claim: EXFILSQUAD alleges leak of UK Police National Legal Database contacts

The ExfilSquad ransomware group has claimed responsibility for leaking 135,000 contact records from the Police National Legal Database. This alleged data leak has raised concerns across UK law enforcement and the wider public sector, despite the claim remaining unverified. Here we examine what is known about the incident, the nature of the data exposed, and the potential risks that could follow.

ExfilSquad Ransomware Group’s Claim: What Happened?

On 26 July 2026, a post appeared on ExfilSquad’s dark web leak site, alleging that the group had obtained and was publishing contact data from the Police National Legal Database (PNLD). This government-facing organisation supports UK law enforcement, and the supposed breach targets sensitive personnel information. The claim surfaced on RedPacketSecurity, which relayed the details with a strong warning: ExfilSquad has a history of posting fabricated victim claims, and this incident remains unverified at the time of writing.

The leak summary specifies that approximately 135,000 law enforcement contact records are involved. These records reportedly include:

  • First and last names of individuals
  • Email addresses
  • Police force area information

The post describes the incident as a data leak, with no mention of file encryption or specific extortion demands. There is no evidence presented of stolen files being made available for download, nor any screenshots or direct samples of the data.

Timeline and Verification Status

The key date associated with this event is 26 July 2026, which corresponds to the date of the ExfilSquad post. No specific details are available regarding when the alleged compromise might have occurred. The timeline is therefore limited to public disclosure on the dark web leak site.

It is important to note that the listing is flagged as unverified by RedPacketSecurity and corroborated by other security sources. ExfilSquad has previously been identified in industry reporting as a group that sometimes posts fabricated or inflated claims of compromise. As referenced in analysis from BankInfoSecurity, some of ExfilSquad’s past announcements have later been proven false or misleading. Thus, while the claim cannot be dismissed outright, it should be treated cautiously pending independent confirmation.

At present, there is no independent evidence available to confirm the authenticity of the breach, the scale of data exposed, or the precise nature of the records involved. The absence of downloadable files, samples, or corroborating victim acknowledgement further limits transparency. However, the specificity of the claimed data—naming the Police National Legal Database and listing types of information—means the threat should not be ignored entirely, especially given the potential for follow-on phishing attacks using police-themed lures.

How the Alleged Data Leak Works

Based on the information provided, the incident is described as a data exfiltration event rather than a classic ransomware attack involving encryption. The post focuses on the exposure of contact information that could be used for social engineering, phishing, or harassment. This aligns with a trend among some ransomware groups that increasingly favour data theft and public shaming over pure encryption-based extortion.

While the technical method of compromise is not detailed in the leak summary, there are several plausible scenarios that could result in such an exposure:

  • Exploitation of unpatched web-facing applications or services used by the Police National Legal Database
  • Spear phishing or credential theft targeting administrative staff
  • Insider threat or accidental data exposure

Given the lack of technical specifics, the above should be considered potential vectors rather than confirmed mechanisms. The focus on contact record details suggests the goal may be more about enabling downstream attacks—such as phishing or impersonation—than securing a ransom payment.

Risks and Implications for Law Enforcement and the Public Sector

If the claims by ExfilSquad prove true, the exposure of 135,000 contact records could have tangible consequences for law enforcement personnel and their organisations. The potential risks include:

  • Targeted phishing attacks using authentic-looking police or legal communications
  • Social engineering aimed at gaining deeper access to police systems or sensitive data
  • Harassment, intimidation, or doxxing of individual officers or staff
  • Damage to public trust in the security of law enforcement systems

The fact that the alleged dataset contains names, emails, and police force area details could enable convincing police-themed phishing campaigns. Even if the claim is fabricated, the media attention alone may prompt opportunistic attackers to target UK law enforcement with tailored phishing attempts using publicly available information.

What Organisations Should Do Next

While this incident remains unverified, UK public sector organisations and law enforcement agencies should remain alert to the risk of police-themed phishing and social engineering. In the near term, key actions include:

  • Raising internal awareness about the risk of phishing emails referencing this or similar incidents
  • Monitoring for suspicious activity involving law enforcement email addresses
  • Coordinating with relevant authorities to verify the authenticity of the breach claim

Organisations should not make assumptions based solely on uncorroborated ransomware posts but should maintain vigilance, especially if any evidence emerges to validate ExfilSquad’s claims.

Originally reported by redpacketsecurity.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call