A security breach at the Police National Legal Database (PNLD) led to the exposure of sensitive information including names, organizations, and work email addresses for police officers, personnel, law enforcement officials, government partners, and clients This article explores police platform disclosure. . An incident reported on July 26 revealed sensitive information such as names and email addresses of individuals who contacted Ask the Police via their platform.

This disclosure may enhance the credibility of targeted phishing attempts aimed at specific law enforcement officials, per UK government guidelines. PNLD is working closely with the Information Commissioner's Office (ICO) and National Crime Agency (NCA), as well as specialized cybersecurity entities, in its investigation.

As of August 3, 2026, neither PNLD's notice nor VenariX's report identified a specific endpoint, permission setting, API route, or supporting log related to PNLD. Microsoft offers tenant-level governance controls that block unauthenticated users from reading Dataverse data while still allowing public form submissions. VenariX advises reviewing Power Pages operator permissions for the Anonymous Users table, adjusting Web API settings, and ensuring legacy OData feeds are configured correctly.

These steps help address the configuration pattern observed by VenariX but do not address any confirmed PNLD (Potential Network Layer Denial of Service) root causes. VenariX couldn’t find any signs of ransomware deployment, malware use, lateral movement, or exploitation of software vulnerabilities in the campaign material they analyzed.