Government Breach: U.K. Police Legal Database Leaks Sensitive Contact Directories

🛡️ Verified Threat IntelDigitalSpying Research Desk
📅 August 3, 2026⏱️ 6 min read

A major government data exposure has compromised sensitive contact directories belonging to the United Kingdom's Police National Legal Database (PNLD). The incident, originating from an unauthenticated Microsoft Power Apps Portals misconfiguration linked to backend Microsoft Dataverse tables on content.powerapps.com, publicly exposed the full names, direct phone numbers, police station affiliations, and official email addresses of thousands of active UK law enforcement officers, judicial officials, and Crown legal advisors.

The Intersection of Low-Code Cloud Portals and Public Sector Risk

Government agencies and law enforcement organizations worldwide have rapidly embraced low-code SaaS platforms—such as Microsoft Power Platform, Power Apps, and ServiceNow—to accelerate administrative workflows and legal publishing portals. While these platforms streamline development, their abstracted permission models introduce severe security blind spots if administrators fail to configure underlying access control lists (ACLs) correctly.

In the PNLD incident, the portal was originally established to provide authorized police constables and criminal justice practitioners with reference access to UK criminal legislation, case law precedents, and legal guidance. However, when connecting the public-facing portal frontend to backend Dataverse entity stores, administrators failed to enforce table-level permission boundaries, leaving raw OData feeds accessible to unauthenticated web crawlers.

Law Enforcement Threat Advisory: Officer OPSEC Compromise

The leak of direct contact directories, internal station locations, and specialized task force designations creates acute physical and operational security (OPSEC) risks for frontline officers, undercover personnel, and witness protection liaisons.

Technical Root Cause: Anonymous OData Exposure in Microsoft Dataverse

Microsoft Power Apps Portals interface with backend relational databases through Microsoft Dataverse (formerly Common Data Service). Dataverse exposes standard RESTful Open Data Protocol (OData) endpoints allowing client-side JavaScript to retrieve, paginate, and display tabular records:

  1. Default Anonymous Table Access: In earlier versions of Power Apps Portals, creating a new list view or portal form did not automatically enforce global table permissions. If an administrator failed to explicitly check the "Enable Table Permissions" toggle in the portal studio, Dataverse treated the underlying table as publicly readable by anonymous internet visitors.
  2. Direct OData API Querying: Adversaries and automated security scanners did not need to interact with the rendered HTML website. By dispatching direct HTTP GET requests to predictable REST API endpoints (e.g., https://[tenant].powerappsportals.com/_api/contacts or /_api/systemusers), unauthenticated users could query raw JSON feeds.
  3. Automated Data Siphoning: Threat actors executed standard OData query parameters (such as $select, $filter, and $top=5000) to extract complete personnel directories, bypassing frontend pagination controls and downloading thousands of confidential records within minutes.
# Threat Actor OData Scraping Sequence (Reconstructed HTTP Telemetry)
GET /_api/contacts?$select=fullname,emailaddress1,telephone1,jobtitle,pnld_force_division HTTP/1.1
Host: pnld-portal.powerappsportals.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
Accept: application/json;odata.metadata=minimal

# Unauthenticated HTTP 200 Response Payload Exfiltrated
{
  "@odata.context": "https://pnld-portal.powerappsportals.com/_api/$metadata#contacts",
  "value": [
    {
      "contactid": "c819a4e2-7634-ef11-840a-000d3a24e912",
      "fullname": "Detective Sergeant [REDACTED]",
      "emailaddress1": "[REDACTED]@met.police.uk",
      "telephone1": "+44 20 7230 ****",
      "jobtitle": "Specialist Crime Command - Major Incident Team",
      "pnld_force_division": "Metropolitan Police Service"
    }
  ]
}
Exposed Data Element Operational Impact Downstream Threat Classification
Officer Names & Rank Compromise of undercover / specialized investigators Targeted intimidation & social engineering
Direct Mobile & Desk Phones Bypassing switchboard verification boundaries Direct voice phishing (vishing) & SIM swapping
Official Police Email Addresses High-fidelity spear-phishing targets Credential harvesting & malicious attachment delivery
Force Division & Role Tags Mapping of specialized regional investigative units Adversary intelligence gathering & counter-surveillance

Downstream Implications: Harassment, Intimidation and UK GDPR Liability

The leak of law enforcement contact directories carries consequences far more severe than traditional commercial data breaches. Organized crime groups (OCGs) and hostile state intelligence services actively harvest leaked government personnel data to:

  • Target Law Enforcement Personnel: Cross-referencing leaked names and phone numbers with public social media accounts enables criminals to identify officers' home addresses, family members, and off-duty routines, facilitating physical threats and witness tampering.
  • Execute High-Fidelity Spear Phishing: Armed with authentic internal nomenclature, department names, and colleague identities, attackers craft highly persuasive spear-phishing campaigns designed to deploy infostealers or ransomware onto sensitive police network domains.
  • Regulatory Penalties under UK GDPR & DPA 2018: The Information Commissioner's Office (ICO) maintains stringent enforcement powers over public bodies failing to protect personal data. Because police employee records carry heightened safeguarding sensitivities, systemic configuration failures expose public agencies to formal enforcement notices and substantial regulatory penalties.

Detection Engineering and Automated Dataverse Scanning

Government IT teams and enterprise cloud security architects must immediately inventory all deployed Power Apps Portals and Power Pages across their Microsoft Entra ID tenants to detect exposed OData endpoints:

# PowerShell Script: Auditing Public Table Permissions across Dataverse Portals
Install-Module -Name Microsoft.PowerApps.Administration.PowerShell -Force
$environments = Get-AdminPowerAppEnvironment
foreach ($env in $environments) {
    $portals = Get-AdminPowerApp -EnvironmentName $env.EnvironmentName | Where-Object {$_.AppType -eq "WebSite"}
    foreach ($portal in $portals) {
        Write-Host "[+] Auditing Portal: $($portal.DisplayName) in $($env.DisplayName)"
        # Probe public _api endpoints for anonymous access
        $url = "$($portal.InternalUri)/_api/contacts"
        try {
            $response = Invoke-RestMethod -Uri $url -Method Get -TimeoutSec 5
            if ($response.value) {
                Write-Warning "[!] CRITICAL EXPOSURE: Anonymous OData access active on $url"
            }
        } catch {
            Write-Host "[OK] Endpoint properly secured: $($_.Exception.Message)"
        }
    }
}

Comprehensive Hardening and Remediation Runbook

Remediating Power Apps and Dataverse data exposure requires establishing rigorous architectural guardrails:

  • Enforce Table Permissions Globally: In Power Pages Management, ensure that the "Enable Table Permissions" setting is set to true across every published table. Explicitly assign web roles (such as Authenticated Users or specific administrative roles) with least-privilege read access. Never grant read permissions to the Anonymous Users web role on tables containing personal data.
  • Disable Anonymous OData Feeds: Review site settings in the Portal Management model-driven app. Set Authentication/Registration/RequiresUniqueEmail and ensure that anonymous API access is explicitly blocked by configuring site setting WebAPI/contacts/enabled to false unless authenticated via Azure AD.
  • Deploy Microsoft Purview Information Protection: Implement sensitivity labels that automatically detect, encrypt, and flag sensitive personnel records within Dataverse, preventing export or public portal synchronization.
  • Audit Tenant-Wide Power Platform Exposure: Utilize the Microsoft Power Platform Center of Excellence (CoE) Starter Kit to maintain automated governance. Deploy automated alerts that notify the SOC whenever a maker provisions an unapproved public-facing website.
  • Provide Immediate Protective Monitoring: For all law enforcement personnel identified in the exposed dataset, implement proactive monitoring on their official email accounts, issue call-screening guidelines on direct desk lines, and provide personal digital safety briefings.
Classification:Cyber Security IntelligenceZero-Day AnalysisDefensive Engineering
🛡️

About the DigitalSpying Research Desk

The DigitalSpying Threat Intelligence Desk is composed of seasoned security researchers, reverse engineers, and blue team architects. Our mission is to publish reproducible, peer-audited threat analyses, hardware security evaluations, and defensive countermeasures.