Real-time ingestion. New datasets every hour.

See your exposure before adversaries do.

Continuous indexing of every public breach, infostealer log, and credential dump. Built for security, fraud, and threat-intel teams that need to know which of their domains, employees, and customers are already in the wild.

SearchIndex lookup — at least one required
Email
is
21,350,654,111
Records indexed
2,320
Datasets
1,849
Sources
Records indexed
21,350,654,111
Datasets in catalog
2,320
Distinct sources
1,849
Ingestion cadence
Real-time

Threat intelligence sources

Three feeds. One unified index.

Every record we ingest is normalized and joined into a single search index. One query reaches the full corpus. Built for teams that need to act on exposure, not assemble it.

Breach data

users.csv
10.6M rows
emailssnpwd_hash
jane.d…@gmail.com***-**-2847$2$10$f9p…
alex.k…@yahoo.com***-**-9134$2$10$xa3…
sam.li…@proton.me***-**-5061$2$10$kl1…

Database dumps from compromised companies. Email, name, postal address, SSN, password hashes — plaintext when the breach was that bad.

What gets exposed

emailnameaddressssndobpassword

Infostealer logs

session_1812.log
redline
user:jane.doe@gmail.com
pass:●●●●●●●●●●●●
card:4532 ●●●● ●●●● 482712/27
wallet:seed: ridge alley orbit shy…
cookie:__Secure-1PAPISID=pUq…

Output from infostealer malware on infected endpoints. Browser-saved credentials, autofill, session cookies, authenticated tokens, saved cards, wallet seeds.

What gets exposed

urlusernamepasswordcookiescredit_cardwallet_seed

Drop sites

onion-mirror · thread/429
3h ago
[DUMP] 50K • ssn + cc fullz
jane.d…|***-**-2847|4532●●●●4827
alex.k…|***-**-9134|5412●●●●1923
sam.li…|***-**-5061|4111●●●●3872
+49,997 more

Files dropped on paste sites, exposed cloud buckets, and adversary forums. Combolists, scraped profiles, exfiltrated SSN dumps, leaked cards.

What gets exposed

emailusernamepasswordssncredit_cardip

Latest intelligence

Recent high-impact disclosures.

The largest collections currently in the catalog, ranked by record count. Click into any to inspect the schema, the source provenance, and run a scoped query.

Browse the full catalog

Att 2021

156,750,195
records
Disclosed Aug 20, 2021database

In March 2024, approximately 70 million records allegedly breached from AT&T were posted to BreachForums by ShinyHunters. The data originally dates to August 2021 and was previously offered for sale before being freely released. AT&T initially denied a breach before later acknowledging data fields specific to their systems were present. The dataset contains AT&T customer records including full names, physical addresses, email addresses, phone numbers, dates of birth, US Social Security Numbers (encrypted), government-issued IDs, and account passcodes. The data is pipe-delimited and includes both current and billing address information for US consumers.

comelec.gov.ph

100,479,164
records
Disclosed Mar 27, 2016other

A breach of the Commission on Elections (COMELEC) of the Philippines, exposing the entire Philippine voter registration database. The archive contains voter registration records (new_id_released.txt, web_id_onhand.txt, web_id_disapproved.txt), overseas absentee voter data (overseas_absentee_all.txt, overseas_absentee_scratch.txt), geographic reference codes, embassy and country codes, web application user accounts with hashed passwords (dbadmin_usersinformation.txt), and internal system user accounts (fum_users.txt). The data includes full names, dates of birth, addresses, fingerprint data, voter identification numbers (VINs), passport numbers, and biometric information for millions of Filipino voters including overseas absentee voters.

zoosk.com

57,554,881
records
Disclosed May 1, 2020other

Breach of Zoosk, an online dating platform. The dataset contains records with registration/activity dates (spanning 2012–2015), usernames, email addresses, and MD5-hashed passwords. This data is consistent with the widely reported Zoosk breach that surfaced around 2020, containing approximately 30 million records originally collected from the platform.

Takoyaki

376,747
records
Disclosed Jun 2, 2026chatter

A SQL database dump containing user records with usernames, email addresses, SHA1-hashed passwords, and plaintext passwords. The dataset appears to be from a gaming or forum community platform. The name 'Takoyaki' likely refers to the platform or service breached. Contains approximately thousands of records based on file size.

ssndob.cc

341,660
records
Disclosed Feb 23, 2014stealer-logs

Web server access logs from SSNDOB (ssndob.cc), an underground marketplace that sold Social Security Numbers and dates of birth of US individuals. The logs dated February 23, 2014 capture HTTP requests including login and registration events with plaintext credentials visible in POST request logs. SSNDOB was a cybercriminal service that traded in PII including SSNs, DOBs, and other personal data on millions of Americans.

soulsplit.net

227,143
records
Disclosed Jun 2, 2026other

User credential dump from SoulSplit, a RuneScape private server (RSPS). Contains usernames, email addresses (many using placeholder 'none@none.com'), and SHA1 password hashes. Data is consistent with a game account database leak from an RSPS community.

Threat briefings

What our analysts are tracking.

Original reporting on emerging breaches, leak campaigns, and the operators behind them. No press releases. No reposts.

Read all briefings

Who uses it

Built for the teams defending exposed identities.

Security operations

Surface credential exposure across your domain. Pivot from a single leaked email to every dataset that record appears in, then push remediation to your IDP in seconds.

Fraud and trust

Detect compromised customer accounts before they're exploited. Score session and signup risk against known-stolen credentials joined to identity attributes.

Engineering

Hit the API from your own infrastructure. Boolean queries, cursor pagination, sparse fields. Same query language as the UI, free for the first 500 calls a day.

For engineers

Wire exposure data into your stack.

Same engine that powers this site, exposed as a clean REST API. Boolean queries. Cursor pagination. Sparse fields. HATEOAS links. Free for the first 500 calls a day, with quota tiers for production traffic.

Read the API docs