Criminals hack Police National Legal Database, leak UK cops' private data on the dark web

British law enforcement comes a cropper in an incident which should - but probably won't - force a rethink of dreadful data storage policies.

Share
A stock image which is absolutely not intended to be a metaphor for the apparent gaps in British cops' data security posture (Image: Unsplash)
A stock image which is absolutely not intended to be a metaphor for the apparent gaps in British cops' data security posture (Image: Unsplash)

A criminal gang has breached the UK Police National Legal Database (PNLD) and claimed to have leaked sensitive data belonging to more than 100,000 police officers and other criminal justice professionals to the dark web.

ExfilSquad - a group believed to have also hacked the Department for Education and other British targets - took responsibility for the attack. The hackers said they had accessed 1.9 GB of data from the PNLD, including roughly 135,000 records.

Most concerningly for the public, the names and email addresses of people who used the PNLD's "Ask the Police" website were also compromised in the incident. This service allows people to ask questions which a legal team then answers within five days.

"The names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web," cops confirmed.

"There is no evidence to suggest that passwords or other security credentials have been compromised."

A "highly unusual" incident

Dr. Ilia Kolochenko, founder of ImmuniWeb and a lawyer practicing in cybersecurity and data protection, on the story, warned that the incident could have "devastating and long-lasting consequences" for law enforcement officers and other criminal justice professionals, potentially leading to "blackmail, extortion and even physical harm to them and their families."

He questioned claims that only a limited amount of data has been compromised, describing the "narrow scope" of the stolen data as "highly unusual".

Dr. Kolochenko added: "It simply does not make sense: if you manage to compromise a production system and you get access to its database, you will likely extract all or almost all data from the database, not just names and emails. Alternatively, this may also mean that the attack was timely detected and contained when the threat actors were in the middle of data exfiltration."

READ MORE: Mayor Sadiq Khan looks to unleash crime-fighting robot police dog in London

Discussing the potential of "Ask the Police leaks", he continued: "The attack has also reportedly compromised identities of people who asked questions online, but not the questions themselves and other data – that may contain highly personal, sensitive and embarrassing information.

"This situation also appears to be highly unrealistic or artificial unless there are some special technical circumstances that remain undisclosed to avoid interference with the ongoing investigation and prosecution of cybercriminals.

"In any case, the attack requires an urgent and scrupulous investigation to clearly understand what exactly have happened in order to protect possible victims as required by law.”

Law enforcement at risk

Dray Agha, Senior Manager, Security Operations Center - EMEA at Huntress, advised officers to be on the look out for phishing attempts and said: "While the absence of compromised passwords is a relief, exposing the names and work emails of UK police and justice staff on the dark web hands cybercriminals a ready-made directory to launch highly targeted spear-phishing and social engineering attacks against the very people defending our justice system"

This warning was backed up by Javvad Malik, lead CISO Advisor at KnowBe4, , who said: "This is far from a low-impact incident. Whenever names, roles, organisations and work email addresses are leaked, it gives attackers all the information they need for convincing phishing, impersonation and social-engineering attacks and can potentially put individuals under personal pressure. "

Britain's database state

This time around, the data related to criminal justice professionals. But it's easy to see the same happening to the 12.5 million ordinary people whose data is stored in police databases.

British cops are notorious for overzealously hoarding data about even the most trifling of crimes on the Police National Computer until people are 100 years old, meaning that folks who got caught committing minor offenses face potential lifelong restrictions on traveling to some countries.

It is spectacularly unlikely that the PNLD breach will prompt politicians or police leaders to address their draconian policy of semi-permanent data storage - even though the incident highlights the utter folly of keeping huge databases of sensitive data in an age when the development of AI hacking tools is ramping up cyber risk to potentially unprecedented levels.

To date, the PNC has not actually been the victim of a publicly announced hack - which is either a not-so-minor miracle or an outright lie.

In 2021, about 150,000 records were accidentally deleted from the UK pancopticon (sorry) during routine "housekeeping".

READ MORE: Russian "Laundry Bear" threat actor rinses Western victims with zero-click exploit

Later that year, a ransomware gang compromised a contractor with PNC connectivity. The Home Office then claimed no police data had been compromised.

Police employees have also been caught accessing the PNC illegally or inappropriately - which is insider misuse rather than an external hack.

As AI reduces the barrier of entry for cybercriminals, it now seems more or less inevitable that the PNC will be hacked and real people's reputations will be ruined by the leaking of data relating to their misdeeds from decades ago.

Which is one of many reasons that cops should start deleting those records immediately - a situation as likely as Britain suddenly halting its brutal decline and becoming the world's wealthiest country again.

We won't be holding our breath for either of these fantasies to come true.

Follow Machine on LinkedIn