The DfE hack led to 607,000 pieces of data being released on the dark web and was thought to have been carried out for financial gain rather than ideological reasons.

The group said online: “Once your company’s data is posted here, it’s NEVER leaving the public eye and it will be passed around the internet FOREVER. The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.”

One source said the majority of officers have used the legal database during their career to complete day-to-day police duties.

The system is responsible for England and Wales, where 145,550 full-time officers are employed,.

Tiff Lynch, chairman of the Police Federation, said: “This reported breach raises serious concerns for officer and staff safety. At a time when cyber threats are becoming increasingly sophisticated, [the police] and its partners must be properly funded to ensure the strongest possible cybersecurity protections are in place to safeguard sensitive personal data.”

Seen as softer targets

Jake Moore, global security adviser at Eset, Europe’s leading cybersecurity company, said: “Unfortunately government organisations are being seen as softer targets because they have not invested enough to properly protect private information.

“The information put on the dark web should not be underestimated. More experienced threat actors see it as highly valuable because it enables them to personalise follow-up attacks, such as phishing or social engineering, which puts even more data at risk.”

Newcastle University has launched an investigation after the group allegedly stole 440,000 pieces of sensitive data including full names, phone numbers, home addresses and email addresses of staff and students.

Mr Moore added: “These attacks are becoming more common as criminals increasingly automate their tactics with ease and exploit the development using AI. The knock-on effect means organisations are facing a far higher volume of attacks, often with far less effort required from the attacker.”

A government spokesman said: “We have dedicated capabilities to respond to cyber incidents, and it would be inappropriate to comment on a live investigation.”

An NCA spokesman told The Times: “We are aware that limited personal details relating to a number of National Crime Agency officers may have been published on the dark web as a result of the incident affecting the police national legal database.”