Three incidents surfaced in the first week of August that have nothing technically in common and one thing structurally in common: in every case, the compromised organisation was one that holds data about other people’s sensitive matters as its core function.

The Police National Legal Database (PNLD) is a Home Office-associated resource used by UK forces and criminal justice professionals — a reference system covering law, powers, and procedure, plus the public-facing “Ask the Police” service.

Attackers identifying themselves as ExfilSquad accessed it and took contact data for more than 100,000 police officers, police staff, and criminal justice professionals: full names, organisations, and email addresses. Data belonging to “Ask the Police” users — members of the public who submitted queries — was also compromised.

The instinct is to look at “names and email addresses” and call it low-severity. That instinct is wrong here, for two reasons.

First, the population. A verified roster of 100,000 serving police officers, each mapped to a specific force, is a targeting list. It is exactly what you need for credential phishing against law enforcement, and law enforcement email accounts are gateways to police national computer access, intelligence systems, and — increasingly — the emergency data request mechanism that platforms honour without a warrant. Fraudulent emergency data requests sent from genuinely compromised police accounts are one of the most effective attacks against tech company disclosure processes, and they have been used repeatedly. This breach makes that easier at scale.

Undercover officers, officers in domestic abuse or organised crime units, and officers whose personal safety depends on their affiliation not being widely known are all in a dataset that is now outside the perimeter.

Second, “Ask the Police” users. People query that service about legal problems they are having. That is not a neutral category.

Switzerland’s federal SharePoint compromise

On July 28, 2026, Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) — the body that runs IT for the federal administration — detected a compromise of its SharePoint servers.

Roughly 200 accounts were affected. Officials stated that no data was stolen other than credentials, though the precise scope has not been fully characterised publicly. BIT closed access, patched, and reset passwords.

The response was fast and by the book, which is worth saying because it usually is not.

The uncomfortable part is the vector. SharePoint has been the subject of sustained mass exploitation campaigns, and the pattern is well known: on-premises SharePoint deployments in government and large enterprise, running behind a patch cycle that cannot keep pace with weaponisation. “Credentials only” is also a phrase that carries less reassurance than it appears to. In an Active Directory–integrated environment, 200 federal credentials are not the end state of an attack; they are the beginning of one. Lateral movement is what those are for.

The law firm wave

Herbert Smith Freehills Kramer LLP and Taft Stettinius & Hollister LLP both reported data breaches to state regulators in recent weeks — adding to dozens of US law firm breaches in 2026.

This is the most under-covered breach category of the year, and it should be the most alarming.

A large law firm holds, in one place: merger terms before announcement, litigation strategy, internal investigation findings, regulatory settlement negotiations, employment disputes with named complainants, immigration filings, medical records in personal injury matters, and the entire correspondence record of clients speaking candidly under an expectation of absolute privilege.

Attorney-client privilege is a legal doctrine about admissibility and compulsion. It says a court cannot make your lawyer testify. It does not encrypt anything. Against an attacker, privileged material is just a well-organised, high-value document repository — and the organisation of it is the attacker’s advantage, because law firms file by matter, and a matter is a story.

The reason law firms are being targeted systematically in 2026 is straightforward: they are where the most valuable version of a company’s secrets lives, held by an organisation with a fraction of that company’s security budget. Firms have been under-invested in security for the same reason hospitals were — the professional culture treats confidentiality as an ethical obligation rather than an engineering problem.

The clients are the ones exposed, and the clients mostly cannot tell which of their counsel is well defended.

What connects them

Each of these organisations is a custodian by function. Police reference systems, federal IT offices, and law firms do not collect data as a side effect of some other business — holding other people’s sensitive matters is the business.

Custodial organisations share a specific failure profile:

  • They aggregate. The value of the target is the concentration, and concentration is unavoidable given what they do.
  • Their users are trusted by default, because the work requires broad internal access to case material.
  • Their security spend is overhead, not product, and it competes with the thing the organisation exists to do.
  • The people harmed are not the customers. The officers in the PNLD did not choose its security posture. The clients of a law firm cannot audit it. Neither has a mechanism to apply pressure.

That last point is the one that never gets fixed by market forces, because the feedback loop is severed. The party bearing the risk has no visibility and no leverage.

What you can actually do

Most of this is out of individual hands, but not all of it:

  1. If you are a UK police officer or staff member, treat any email referencing PNLD, force IT, or credential re-validation as hostile until verified by a second channel. Your work address is confirmed to be in attacker hands.

  2. If you have a matter with outside counsel, ask your firm three questions in writing: do you have MFA on all remote access, do you encrypt matter files at rest, and have you had a breach in the last 24 months. Client pressure is the only mechanism that has ever moved law firm security budgets. Firms answer procurement questionnaires from large corporate clients; individual clients almost never ask.

  3. Assume email to counsel is the weak link. For genuinely sensitive matters, use the firm’s secure portal rather than email attachments, and ask them to use it too.

  4. For everyone: unique passwords and phishing-resistant MFA. Credential-theft breaches like the Swiss one only cascade because credentials are reused. Passkeys are the right answer here, with the caveats researchers demonstrated this week — the cryptography is sound, the surrounding implementations are where things go wrong.

  5. Check haveibeenpwned.com and enable notifications. It costs nothing and it is the only breach alerting most people will ever get.

The pattern

Breach coverage is organised around record counts, because record counts are comparable and make headlines. A hundred thousand names and email addresses ranks low by that metric.

But the harm from a breach is not a function of how many records were taken. It is a function of what the aggregation enables — and a verified roster of every serving officer in a national police service enables things that a hundred million leaked marketing emails never could.

The organisations holding the most consequential data are frequently the ones with the smallest security budgets, because their consequence comes from their role rather than their size. That mismatch is the whole story of 2026’s breach year.