Over 114,000 UK police officers had their personal data stolen and posted on the dark web. The group behind it, ExfilSquad, made its ransomware debut by breaching government departments including the Ministry of Defence, Home Office, National Crime Agency, and Crown Prosecution Service. Names, email addresses, and work details of officers listed in the Police National Legal Database got dumped publicly in late July.

The Times confirmed the leak was real. Beyond police, ExfilSquad also grabbed data from 2,615 CPS staff, 617 Home Office employees, 588 NCA operatives, and 402 MoD personnel. The group claims it hacked 15 organizations total, naming Microsoft and the UK Department for Education alongside the government agencies. Researchers doubted some of those claims when the listing first appeared, but the police database breach checked out.

ExfilSquad's pitch to victims reads like a crude protection racket. "Once your company's data is posted here, it's NEVER leaving the public eye and it will be passed around the internet FOREVER," the group wrote. They gave targets until August 5 to pay up, framing the ransom as cheaper than litigation costs. The Times reported the operation looks financially motivated rather than political.

Like most ransomware outfits, ExfilSquad will likely demand cryptocurrency for the ransom. That lets them funnel payments through mixers, privacy coins, and untracked exchanges to clean the money. Similar hacking groups have already gone this route. The UK government is meanwhile planning restrictions on public sector organizations paying ransoms at all, though whether that deters groups hitting government agencies remains unclear.

This article is informational and does not constitute financial or security advice. Readers should consult relevant authorities and cybersecurity professionals regarding data protection measures.