A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]

A cyberattack on the UK's Police National Legal Database (PNLD) has led to the compromise of contact data for over 100,000 police officers and other criminal justice professionals. The incident, detected on Sunday, July 26, was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records.
PNLD, an online legal resource used by the 43 Home Office police forces in England and Wales, as well as the British Transport Police for over 30 years, confirmed the breach. The service also operates "Ask the Police," a public-facing website.
According to PNLD, the breach exposed the full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. Additionally, the names and email addresses of users who submitted questions through the "Ask the Police" platform were also compromised.
The ExfilSquad group claimed responsibility for the attack and published sample data to substantiate its claims. The group also demanded a ransom to prevent the release of the remaining stolen data. ExfilSquad asserts it stole 1.9 GB of data from PNLD, comprising approximately 135,000 records, which includes information belonging to 114,000 PNLD subscribers and 21,000 "Ask the Police" users.
PNLD has initiated an investigation into the incident with the assistance of cybersecurity experts and the National Crime Agency (NCA). The organization stated that no evidence has been found to suggest that passwords or other security credentials were compromised.
The affected party confirmed that PNLD does not store confidential information related to victims, witnesses, or offenders, and no such data was impacted in the breach. All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner's Office (ICO) has also been notified.
While PNLD has confirmed the breach and the publication of contact details, it has not publicly attributed the intrusion or disclosed the method by which attackers gained access to its systems. ExfilSquad is known for other recent cyberattacks, including one on the American semiconductor company Analog Devices.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.