Aug 03, 2026 · 7 min read
ExfilSquad Leaked 135,000 Police Work Email Addresses
A previously unknown extortion crew posted samples from the UK Department for Education and the Police National Legal Database on a dark web leak site on July 26, 2026. The education dump is bigger. The police one is worse.
The bigger number is not the dangerous one. When ExfilSquad listed its haul, the headline figure was roughly 607,000 records from the Department for Education, and that is the number most coverage led with. Underneath it sat a quieter set: about 135,000 records from the Police National Legal Database, carrying names, employing forces, and work email addresses for serving officers and criminal justice staff. The DfE says the risk to individuals is not high. That is a judgement about privacy harm to any one person. It is not a judgement about what an attacker can build once they know exactly who works where and how to reach them.
Key Takeaways
- ExfilSquad published samples from the UK Department for Education and the Police National Legal Database on a dark web leak site on July 26, 2026, claiming more than 740,000 records between them.
- The PNLD portion covers roughly 135,000 records containing names, employing forces, and work email addresses of police officers and criminal justice staff, plus names and addresses of members of the public who used its Ask the Police service.
- The DfE portion covers about 607,000 records drawn from its Help Desk Self Service Portal and its Turing Scheme Portal, including names, job titles, email addresses and phone numbers.
- DfE described its 600,000 figure as lines of data rather than a count of individuals affected and rated the risk as not high, while PNLD, hosted by West Yorkshire Police, called the immediate risk low.
- The National Crime Agency is investigating, the National Cyber Security Centre is supporting law enforcement, and both organisations referred themselves to the Information Commissioner's Office.
What Did ExfilSquad Actually Take?
ExfilSquad took two unrelated British government contact databases and published samples of both to pressure payment. The Record reported that the DfE material came from the department's Help Desk Self Service Portal and its Turing Scheme Portal, and that the group is demanding a ransom for not publishing the rest. No systems were encrypted. This is pure data theft extortion, the model steadily displacing classic ransomware because it needs no payload on the victim's estate at all.
The file sizes tell you more than the record counts do. FutureScot reported the DfE set at over 440 megabytes uncompressed plus 7,000 Turing Scheme records, and the PNLD set at 1.9 gigabytes. Divide those out and the arithmetic is stark: the education dump averages roughly 0.7 KB per record, the police dump roughly 14 KB. Twenty times the payload per person, for a database described in the same language of contact details. Something in the PNLD extract is far fatter than a name and an address, and nobody has explained what.
Why Does "Lines of Data, Not People" Matter?
It matters because it turns the story into a counting dispute rather than a capability transfer, and only one of those is the security question. The DfE's position, that 600,000 refers to lines of data rather than a count of individuals affected, is probably true. Helpdesk exports duplicate heavily. One school administrator who raised nine tickets is nine lines.
But deduplication does not reduce an attacker's options. Every duplicate line still carries a working address, and duplicates are themselves signal: the contact who appears forty times is the person who runs the account. As IBTimes UK reported, PNLD stated its database does not hold confidential victim, witness or offender information and assessed the immediate risk as low. That is a reasonable statement about content and a weak one about consequence. The same framing showed up when hackers hit the US federal courts, and the PACER filing system breach was likewise described in terms of what had not been touched.
Why Are Verified Work Email Addresses the Real Payload?
Because the hardest part of a targeted email campaign is not writing the message, it is knowing who to send it to, and this leak solves that for free. A normal phishing operation against a police force starts with guesswork: scrape LinkedIn, infer the address format, spray, and watch most of it bounce. A PNLD extract removes every one of those steps. The addresses are real, currently in use, tied to a named individual, and mapped to a specific employing force.
It also hands the attacker a plausible pretext. Every person on that list uses PNLD, so a message about PNLD account verification, a portal migration, or a mandatory password reset lands in a context the recipient already recognises. The NCSC's phishing guidance is explicit that the credible ones borrow a service the target genuinely uses. And multi factor authentication is not the backstop people assume: adversary in the middle kits now proxy the real login page and steal the session cookie after the code is entered, the same technique behind recent Outlook session hijack campaigns.
Then there is the slice almost nobody has discussed. Alongside the officer records sit names and addresses of members of the public who used the Ask the Police service, people who had no reason to expect their question would become a line in a leaked file. Officers signed up for a public role. Those correspondents did not.
Who Is ExfilSquad?
ExfilSquad is a new extortion brand that surfaced only days before these listings, with no established track record to judge it by. FutureScot noted the group's operations began within days of the reporting and that it has claimed victims across the United States, the United Kingdom, Sweden and Nigeria, listing 14 alleged targets on a single day. IBTimes UK reported that most of those claims, including one naming Microsoft, remain independently unverified.
That mixture matters when you read the numbers. A crew this young inflates, and some of the 14 will be resold or duplicated from older leaks. But a government body has now confirmed the core of the claim, which is the part that counts. The playbook is not new: steal a contact database, publish a teaser, wait. It is the same commercial logic behind the ShinyHunters leaks that fed a wave of extortion emails, where the stolen records mattered far less than what could be sent to the people inside them. The British government does not pay ransoms as a matter of principle, which means the sensible planning assumption is that this data goes public in full.
What Should You Do If Your Address Is in This Dump?
Treat the leak as an inbound campaign that has not started yet rather than an incident that has finished. Practical steps, in the order they pay off:
- Assume any PNLD or DfE themed email is hostile until proven otherwise. Account verification, portal migration and urgent password reset messages referencing these systems are the obvious lure. Navigate to the service yourself instead of clicking through.
- Move to phishing resistant authentication where you can. Hardware security keys and passkeys defeat adversary in the middle proxies because the credential is bound to the real domain. Codes from an app are not.
- Watch the phone as well as the inbox. The DfE records include phone numbers and job titles, which is everything a caller needs to sound like a colleague. Callback verification on a known number should be routine, not awkward.
- Report attempts centrally, not individually. Suspicious emails go to the NCSC Suspicious Email Reporting Service, which is how a pattern across 43 forces gets spotted before it succeeds anywhere.
- For organisations: audit third party portals now. Both compromised systems were self service front ends bolted onto a public body. Enumerate every portal you run, know what it exports, and check the ICO's breach reporting requirements before you need them.
Looking Ahead
Two investigations run in parallel: the National Crime Agency on the intrusion, the Information Commissioner's Office on the self referrals, with the NCSC supporting. Neither will tell you soon whether anyone acted on the data. That is the honest state of it.
The ICO has form for closing cases like this with paperwork rather than penalties. It issued only a reprimand to the UK criminal records office after three separate intrusions went undetected for seven months.
The measurable outcome will not be the ransom, which will not be paid. It will be whatever arrives in 135,000 police inboxes over the coming months, addressed correctly, referencing a system the recipient really uses, from a sender who already knows their employing force. Contact details are only boring right up to the moment someone uses them.