Lexipol Data Breach (2025)
If you are a customer of Lexipol, here’s what’s now in circulation.
In February 2025, the public safety policy management systems company Lexipol suffered a data breach. Attributed to the self-proclaimed "Puppygirl Hacker Polycule", the breach exposed an extensive number of documents and user records which were subsequently published publicly. The breach included over 670k unique email addresses in the user records, along with names, phone numbers, system-generated usernames and passwords stored as either MD5 or SHA-256 hashes.
Lexipol customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On February 11, 2025, Lexipol disclosed a breach that exposed records of 673,000 users. The public safety policy management systems company lost names, email addresses, phone numbers, usernames, and passwords stored as either MD5 or SHA-256 hashes. The incident has been attributed to a group calling itself the Puppygirl Hacker Polycule, which published the material online.
Reported Details of the Breach
Public reporting indicates the stolen data set contained more than 670,000 unique email addresses. Alongside those were full names, phone numbers, system-generated usernames, and password hashes. The breach occurred in February 2025 and the files were later posted publicly. Industry research from sources such as DoxxScan™ continuous monitoring lists the incident and confirms the categories of information involved. No evidence has surfaced that the passwords were stored in plain text, but the presence of hashes means determined attackers can still attempt to crack them offline.
Why This Matters for You and Your Family
If your email or phone number appears in the Lexipol breach, attackers now hold a ready-made starting point for targeted attacks against you and anyone connected to you. A single exposed password hash can lead to account takeovers on other services where you reuse credentials. Phone numbers enable SMS phishing and SIM-swapping attempts. For families, the risk extends to shared accounts, children’s online profiles, and gaming usernames that often link back to the same household address or parent email. Once initial data appears on underground forums, it rarely stays there.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The Doxxing and Identity-Chain Risks
Credential leaks like this one frequently cascade into doxxing chains. Attackers combine the Lexipol usernames and emails with information from gaming platforms, social media, and data-broker records to build a complete picture of your identity. A child’s gaming account tied to a parent’s breached email can become an entry point for harassment or further extortion. The exposed phone numbers make it easier to link anonymous handles to real-world addresses. These identity chains grow quickly once the first thread is pulled.
Puppygirl Hacker Polycule Track Record
Public reporting attributes this breach to the self-proclaimed Puppygirl Hacker Polycule. The group emerged in recent years and has targeted organizations whose data might embarrass or expose individuals, including government-adjacent and public-service providers. Their typical playbook involves initial access through unpatched systems or stolen credentials, followed by broad exfiltration of user databases and documents. They then publish the material on leak sites with theatrical flair, often setting short deadlines for payment before full release. Past victims have included smaller tech firms and niche service providers. Exact prior victim counts remain unclear from open sources, but the group’s pattern of rapid publication matches the Lexipol incident.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup to remove what you can.
- Rotate the password you used at Lexipol anywhere else it appears, replace it with a unique one, and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches your family is caught in hours, not months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that often chain back to the same address or parent credentials.
- Let remediation specialists handle takedown requests across data brokers and leak sites for you while you focus on securing the exposed accounts.
The Lexipol breach is a reminder that even organizations serving public safety can lose control of the personal data they hold. Taking concrete steps now limits how far attackers can travel down the identity chain that begins with this leak. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts. Start your DoxxScan trial today to close the gaps before the next breach appears.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…