ctipilot.ch
← Back to Daily brief 2026-08-04
HIGHupdateNATOA1incident

PNLD confirms the police contact-data breach and names a second affected service; researchers trace the ExfilSquad campaign to anonymously readable Power Pages portals, but not PNLD's own root cause

discovered 2026-08-04 04:49 UTCrun 2026-08-04T0411Z-intel3 sourcesmulti-source

UPDATE · originally covered UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated (2026-07-31)

the earlier entry recorded the Police National Legal Database as "affected" with a 135,000-record figure taken from third-party reporting while the Home Office declined to comment. Three things have changed, and one of them is a correction to the numbers.

The victim has now published its own statement. PNLD, operated by West Yorkshire Police, confirms that "Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web", that "There is no evidence to suggest that passwords or other security credentials have been compromised", that the incident was identified on Sunday 2026-07-26, that all affected organisations were contacted, and that it is working with the National Crime Agency and specialist cyber-security firms with the Information Commissioner's Office notified (PNLD, 2026-08-03). The statement adds a second affected service the earlier entry did not carry: Ask the Police, the public enquiry site PNLD hosts, from which names and email addresses of citizens who had previously submitted questions were also published. PNLD stresses what it is not — not the Police National Computer, not the Police National Database, not a crime-recording system, and holding no confidential material on victims, witnesses or offenders (The Hacker News, 2026-08-03).

On scope, the correction runs the other way from the usual pattern. PNLD's notice describes the exposed fields and gives no victim total at all, and as of 2026-08-03 it had not disclosed how many people were affected, when the intrusion began, how long access lasted or how much data was taken. The 108,429 figure circulating alongside this incident comes from PNLD's own 2025-26 annual summary of police registrations across all 43 Home Office forces — and the reporting is explicit that "That is a user-base figure, not a breach-victim count." Treat both that number and the earlier 135,000 as unconfirmed for scope purposes.

The access path is the transferable part, and it is a campaign-level finding rather than a PNLD root cause. VenariX reviewed data samples associated with 11 of the 15 organisations ExfilSquad listed and found the structure and field formatting consistent with Microsoft Dataverse exports across all 11 — @odata.etag, @OData.Community.Display.V1.FormattedValue and @Microsoft.Dynamics.CRM.lookuplogicalname artefacts across contacts, accounts, incidents, emails, annotations, leads, system users and business units. Its assessment is that the data came out of public Microsoft Power Pages portals configured to let anonymous visitors read Dataverse records, through the portal Web API /_api/<EntitySetName> route or a legacy /_odata feed. Crucially there is no exploit in the chain: "VenariX has not identified evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability." VenariX reproduced the condition once, against the City of Houston's public Power Apps portal serving Houston 311, which returned incident records without authentication in a form consistent with what ExfilSquad published (VenariX, 2026-07-29). VenariX is equally explicit about its own limit: the evidence does not confirm that every listed organisation was reached the same way, or through the same configuration issue. PNLD is not mentioned anywhere in that research at all, and the reporting that connects the two is explicit about the gap — as of 2026-08-03 neither PNLD's notice nor VenariX's report identified a PNLD-specific endpoint, permission setting, API route or supporting log, so "At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach" (The Hacker News, 2026-08-03). What is corroborated is only the platform: PNLD's 2023-24 annual summary states the database uses Microsoft Power Platform, and the breach-notice page references assets on Microsoft's content.powerapps.com domain.

This also revises the earlier entry's editorial line. That entry carried an assessment that ExfilSquad's 15-victim list was more likely fabricated than genuine. The correct current read is narrower and more useful: the individual claim still deserves base-rate scepticism, but the method is now evidenced — 11 structurally consistent Dataverse sample sets, one reproduced live, one listed company (Frontier Airlines) having already confirmed unauthorised access to a data storage account on 2026-07-09 without attributing it — so the method should be swept for locally regardless of whether any given listing is real.

Information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web.

There is no evidence to suggest that passwords or other security credentials have been compromised.

Police National Legal Database

VenariX has not identified evidence of ransomware deployment, malware use, lateral movement, or exploitation of a software vulnerability.

VenariX 2026-07-29

That is a user-base figure, not a breach-victim count.

At this stage, the Power Pages link remains a hypothesis to test rather than an explanation of the PNLD breach.

The Hacker News 2026-08-03

Defender actions

  • From an unauthenticated browser session, request /_api/contacts, /_api/accounts, /_api/incidents, /_api/emails, /_api/annotations and /_odata against every externally-reachable Power Pages or Power Apps portal your organisation operates, and treat any 200 response returning record bodies as a live data exposure to close today by removing table permissions from the Anonymous Users web role.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Collection TA0009
T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.