Hackers allegedly linked to a group called ExfilSquad have leaked the personal information of more than 100,000 law enforcement personnel. The stolen data, which includes names and contact details, was reportedly uploaded to the dark web following breaches of several major UK government agencies.

Advertisement

The 100,000-officer breach across the Home Office and MoD

A massive cyberattack has compromised the personal data of over 100,000 police officers across the United Kingdom. The breach targeted several high-level UK government institutions, including the Home Office, the Ministry of Defence (MoD), the Crown Prosecution Service (CPS), and the National Crime Agency (NCA).

The stolen information, which reportedly consists of full names and contact details, has been made available on the dark web. According to reports from The Times, the hacking group ExfilSquad is allegedly responsible for the leak. This exposure has caused significant alarm among law enforcement agencies, as the data provides a direct roadmap to the identities and locations of those serving in the police force.

A pattern of vulnerability from the DfE breach to ExfilSquad

This incident follows a recent security failure at the Department for Education (DfE) involving more than 500,000 records. As The Times reported, ExfilSquad is suspected of being the architect behind both the DfE breach and this current attack on law enforcement agencies . This pattern suggests a coordinated campaign targeting the digital infrastructure of the British government.

The repeated targeting of public institutions highlights a growing trend of cyber espionage and sophisticated digital threats. Experts warn that these vulnerabilities pose a significant risk to both national security and individual privacy . The frequency of these attacks indicates that current cybersecurity protocols may be insufficient to deter newly emerged hacking groups.

Tiff Lynch’s warning on officer safety and funding

Tiff Lynch,the national chairman of the Police Federation, has called for immediate increases in cybersecurity funding to protect personnel. lynch emphasized that the growing sophistication of these threats requires a robust defense to safeguard the well-being of those who protect the public. The Federation has expressed grave concerns regarding the physical safety of officers whose information is now public.

The exposure of contact information creates significant safety risks for officers involved in high-risk criminal investigations. One anonymous official, whose own details were compromised in the leak, described the situation as deeply unsettling. The official noted that the exposure of personal information could lead to direct dangers for those working in sensitive roles.

What the Home Office and NCA have yet to disclose

The Crown Prosecution Service (CPS) and the National Crime Agency (NCA) have confirmed they are aware of the breach and are conducting investigations. However, the government has not yet provided a detailed breakdown of the specific data types stolen beyond names and contact info. It remains unclear if more sensitive identifiers, such as home addresses or internal identification numbers, were also compromised.

The Home Office has acknowledged the ongoing investigation but has provided very few specifics regarding how the breach occurred. It is currently unknown how ExfilSquad managed to penetrate the systems of multtiple high-security agencies simultaneously. Authorities are still working to mitigate the risks and prevent further exploitation of the stolen data .