The Register Home Page

back to article Police National Legal Database confirms data theft after dark web leak

The Police National Legal Database (PNLD) is the latest UK public sector outfit to admit that cybercriminals made off with its data, including the names and work email addresses of police officers, justice staff, government partners, and customers. The legal lookup service relied upon by police forces and criminal justice …

  1. Arkitekt

    Sounds about right. Just what I would expect from such a well-run organization...

  2. Paul Herber Silver badge

    It's a fair cop.

    1. Korev Silver badge
      Coat

      I guess they use copper cabling in their datacentre

      1. Paul Herber Silver badge

        and fuzzy logic.

  3. Gavsky

    Oh, that's alright then. Hopefully no major criminals or terrorists get hold of the data, eh? I keep banging on about encryption as standard for data like this - but that's never spoken of in any reports I've seen. Perhaps El Reg could ask the question of major businesses, organisations, Government departments? Individual data isn't in constant use, it could be decrypted 'on the fly' as required.

    1. Yet Another Anonymous coward Silver badge

      But this was a police database and only criminals and terrorists use encryption.

      This can only be prevented by requiring a government ID card to go online

  4. Tron Silver badge

    Design out the problem.

    Keep data stashes on a system or network that never connects to the public internet. Connection to the public internet is the primary threat. Whack-a-mole attempts to protect systems connected to the net are the road to hell. Keep as much offline as you can and airgap. If you need two screens and two keyboards on every desk, do it. It's a hell of a lot cheaper than dealing with malware and data theft.

    1. MatthewSt Silver badge

      Re: Design out the problem.

      Are they building their own fixed line and mobile networks too? Actually probably best not think too hard about the mobile network part of that question.

  5. vulture65537

    Email work addresses

    Years ago when I was in a company that provided IT work to some police forces there was an encrypted email service called CJSM: Criminal Justice Secure Mail. But the customer contacts did not always use it, or their work addresses - they sometimes sent from Gmail.

    If they want secure data that kind of thing needs to be banned and enforced.

    I can still remember the name of the man with by far the highest number of password resets.

  6. Anonymous Coward
    Anonymous Coward

    To be fair

    ‘whatsallthisthen’ was a decent password in 1998.

    1. Anonymous Coward
      Anonymous Coward

      Re: To be fair

      As was LOLOLO...

  7. Anonymous Coward
    Anonymous Coward

    A bit more of a tabloid style coverage here:

    https://www.thecanary.co/uk/2026/08/03/hackers-exfilsquad-police-staff/

  8. Mickey Porkpies
    FAIL

    Gov BS about online cloud first

    with no idea how to protect data and believe consultants about how secure cloud is. Will they ever learn? nope

  9. excperr

    "According to the PNLD, the leaked information includes the names, organizations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and customers."

    Are their "customers" criminals by chance? :)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon