The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals.
In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and work email addresses belonging to police officers, staff, government partners, and customers.
The announcement also said the stolen information was already published on the dark web, adding that there is “no evidence to suggest that passwords or other security credentials have been compromised.” How the attackers worked their way in was not disclosed in the announcement.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- UK hospital meltdown after ransomware worm uses NSA vulnerability to raid IT
May 12, 2017
UK hospitals have effectively shut down and are turning away non-emergency patients after ransomware ransacked its networks. Some 16 NHS organizations across Blighty – including several hospital trusts such as NHS Mid-Essex CCG and East and North Hertfordshire – have had their files scrambled by a variant of the WannaCrypt, aka WanaCrypt aka Wcry, nasty. Users ...
- UK businesses concerned about cyber-risks linked to smart energy tech
May 8, 2017
The latest PwC B2B Energy Survey found that 65 percent of UK businesses are significantly concerned about the issue of cyber-risks and over half (51 percent) are worried that their client data isn’t handled with enough security by their energy supplier. The research included responses from more than 500 UK businesses. If their energy supplier fell victim ...
- Investigatory Powers Act: Back doors, black boxes, and tech capability regs
May 8, 2017
The Home Office has launched an under-the-radar consultation on a critical step in the implementation of the Investigatory Powers Act (IP Act): the regulations on technical capability notices. The Open Rights Group has recently revealed details of the proposed regulations. Under the IP Act, a technical capability notice can be issued to a telecommunications operator by the secretary of state ...
- Debenhams Data Breach Affects 26K Customers, Payment Details Exposed
May 5, 2017
Personal data of up to 26,000 people was exposed due to a data breach affecting customers of Debenhams Flowers, the retailer’s florist arm. According to Debenhams, the site is actually operated by Ecomnova, which is a third-party supplier. Therefore, customers of other services it provides have not been affected in any way. On the other hand, Ecomnova ...
- Hundreds of Fake UK Bank Sites Exposed, Pose High Risk for Customers
May 3, 2017
Hackers have registered over 300 domains with names similar to those of several popular British banks, which they use to trick customers into handing over personal details or login data. According to DomainTools, a company handling domain names and DNS-based cyber threats, 324 such domains were discovered only in relation to banks in the United Kingdom, ...
- TalkTalk hack attack: Two men plead guilty to customer data theft
April 27, 2017
Two men have pleaded guilty to hacking into TalkTalk’s website in October 2015 and stealing thousands of customer records containing sensitive data. Matthew Hanley, 22, of Devonshire Drive, Tamworth admitted to three offences under the Computer Misuse Act. The Metropolitan Police said that he confessed to breaching TalkTalk’s site, had obtained files that would enable the ...

