Skip to content
Back to Blog
high severity February 11, 2025 · 3 min read

Lexipol Data Breach (2025)

If you are a customer of Lexipol, here’s what’s now in circulation.

In February 2025, the public safety policy management systems company Lexipol suffered a data breach. Attributed to the self-proclaimed "Puppygirl Hacker Polycule", the breach exposed an extensive number of documents and user records which were subsequently published publicly. The breach included over 670k unique email addresses in the user records, along with names, phone numbers, system-generated usernames and passwords stored as either MD5 or SHA-256 hashes.

Lexipol Data Breach (2025)

On February 11, 2025, Lexipol disclosed a breach that exposed records of 673,000 users. The public safety policy management systems company lost names, email addresses, phone numbers, usernames, and passwords stored as either MD5 or SHA-256 hashes. The incident has been attributed to a group calling itself the Puppygirl Hacker Polycule, which published the material online.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Reported Details of the Breach

Public reporting indicates the stolen data set contained more than 670,000 unique email addresses. Alongside those were full names, phone numbers, system-generated usernames, and password hashes. The breach occurred in February 2025 and the files were later posted publicly. Industry research from sources such as DoxxScan™ continuous monitoring lists the incident and confirms the categories of information involved. No evidence has surfaced that the passwords were stored in plain text, but the presence of hashes means determined attackers can still attempt to crack them offline.

Why This Matters for You and Your Family

If your email or phone number appears in the Lexipol breach, attackers now hold a ready-made starting point for targeted attacks against you and anyone connected to you. A single exposed password hash can lead to account takeovers on other services where you reuse credentials. Phone numbers enable SMS phishing and SIM-swapping attempts. For families, the risk extends to shared accounts, children’s online profiles, and gaming usernames that often link back to the same household address or parent email. Once initial data appears on underground forums, it rarely stays there.

The Doxxing and Identity-Chain Risks

Credential leaks like this one frequently cascade into doxxing chains. Attackers combine the Lexipol usernames and emails with information from gaming platforms, social media, and data-broker records to build a complete picture of your identity. A child’s gaming account tied to a parent’s breached email can become an entry point for harassment or further extortion. The exposed phone numbers make it easier to link anonymous handles to real-world addresses. These identity chains grow quickly once the first thread is pulled.

Puppygirl Hacker Polycule Track Record

Public reporting attributes this breach to the self-proclaimed Puppygirl Hacker Polycule. The group emerged in recent years and has targeted organizations whose data might embarrass or expose individuals, including government-adjacent and public-service providers. Their typical playbook involves initial access through unpatched systems or stolen credentials, followed by broad exfiltration of user databases and documents. They then publish the material on leak sites with theatrical flair, often setting short deadlines for payment before full release. Past victims have included smaller tech firms and niche service providers. Exact prior victim counts remain unclear from open sources, but the group’s pattern of rapid publication matches the Lexipol incident.

What to do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup to remove what you can.
  • Rotate the password you used at Lexipol anywhere else it appears, replace it with a unique one, and enable 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches your family is caught in hours, not months.
  • Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that often chain back to the same address or parent credentials.
  • Let remediation specialists handle takedown requests across data brokers and leak sites for you while you focus on securing the exposed accounts.

The Lexipol breach is a reminder that even organizations serving public safety can lose control of the personal data they hold. Taking concrete steps now limits how far attackers can travel down the identity chain that begins with this leak. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts. Start your DoxxScan trial today to close the gaps before the next breach appears.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Lexipol customer?
Lexipol is one listing. Your email is probably in others.
673K accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed February 11, 2025
Last reviewed July 22, 2026
Affected 673K
Data exposed Email addressesNamesPasswordsPhone numbersUsernames
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email