In April 2026, a threat actor calling itself 'kittykatkrew' breached an Arkansas State Crime Lab database and leaked the full personnel directory plus active court calendars. The exposed data included names, work emails, phone numbers, job titles, and employing agencies for prosecutors, police, and city officials across Arkansas, alongside defendant names, court dates, forensic-analyst assignments, and prosecutor contacts.
What happened
On April 23, 2026, the dark-web monitoring outlet Dark Web Informer reported that a threat actor calling itself "kittykatkrew" posted a breach of an Arkansas State Crime Lab portal on a dark-web leak forum. According to the public summary, the breach came through the lab's web portal at lasso.crimelab.arkansas.gov.
The personnel directory covers portal users across Arkansas: prosecutors, police officers, and city officials, listed with full names, work emails, phone numbers, job titles, and employing agencies. The court-calendar data covers defendant names, scheduled court dates, assigned forensic analysts, and prosecutor contact information. Account metadata, including last-login timestamps, was also exposed.
The full Dark Web Informer article requires a paid subscription. The public preview is enough to establish the scope of the breach and why it matters for Arkansas law-enforcement personnel.
No public response from the Arkansas State Crime Lab or state officials had been reported at the time of writing, and no update on the portal's status or any law-enforcement follow-up has surfaced. Anyone in the leaked directory should assume the data is circulating and act on that basis rather than wait for an official notice.
How it started
A state crime lab holds data tied to active investigations and to the people who work them. Its portal grants access to prosecutors, police, and analysts across the state, which is why a breach of the user directory matters as much as the case data: it ties names and roles to specific Arkansas agencies. No source has reported what the actor did with the directory after posting it. The general risk is well understood, though. A directory that pairs a name with an agency is a starting point for a broker-side search for the home address behind that name.
What this means for you
If you are a prosecutor, police officer, forensic analyst, or city official in Arkansas whose name and work email are in this leak, the first exposure is the directory entry itself. The larger risk is what someone builds from it: a name-and-agency lookup, then a broker-side search for the home address tied to that name and the people who live there.
Arkansas has thin officer-specific privacy law. The FOIA personal-contact exemption at Ark. Code §25-19-105(b)(13) keeps the home phone numbers, personal emails, and home addresses of nonelected public employees out of the records their employer releases. It does not reach a directory already circulating on a dark-web forum. Arkansas has no Daniel's Law, the New Jersey statute that lets officers and immediate family in the same household order brokers to take down their home address and unpublished phone. The federal DPPA, which restricts release of the personal data in your motor-vehicle record, is the floor for DMV-sourced information.
The step you can control: get your home address and unpublished phone off broker pages, so the leaked directory entry cannot be cross-referenced into a residence. Frontline Privacy files opt-outs across the major data-broker sites and keeps checking, refiling when your information comes back.
What reduces this risk
Arkansas has no Daniel's Law analog, the New Jersey-style statute that lets police, prosecutors, and immediate family in the same household order data brokers to take down their home address and unpublished phone. The state's FOIA personal-contact exemption (Ark. Code §25-19-105(b)(13)) covers the contact information of nonelected public employees held in employer records, not data already published on a leak forum. Once a personnel directory like this is in circulation, the names and emails get cross-referenced against broker pages to tie each person to a home address. The step you can control is upstream: keep your home address and phone off broker pages so the leaked directory entry does not connect to a residence. Frontline Privacy files opt-outs across the major data-broker sites and keeps re-checking, refiling when your information reappears.