See your exposure before adversaries do.
Continuous indexing of every public breach, infostealer log, and credential dump. Built for security, fraud, and threat-intel teams that need to know which of their domains, employees, and customers are already in the wild.
Threat intelligence sources
Three feeds. One unified index.
Every record we ingest is normalized and joined into a single search index. One query reaches the full corpus. Built for teams that need to act on exposure, not assemble it.
Breach data
Database dumps from compromised companies. Email, name, postal address, SSN, password hashes — plaintext when the breach was that bad.
What gets exposed
Infostealer logs
Output from infostealer malware on infected endpoints. Browser-saved credentials, autofill, session cookies, authenticated tokens, saved cards, wallet seeds.
What gets exposed
Drop sites
Files dropped on paste sites, exposed cloud buckets, and adversary forums. Combolists, scraped profiles, exfiltrated SSN dumps, leaked cards.
What gets exposed
Latest intelligence
Recent high-impact disclosures.
The largest collections currently in the catalog, ranked by record count. Click into any to inspect the schema, the source provenance, and run a scoped query.
Att 2021
In March 2024, approximately 70 million records allegedly breached from AT&T were posted to BreachForums by ShinyHunters. The data originally dates to August 2021 and was previously offered for sale before being freely released. AT&T initially denied a breach before later acknowledging data fields specific to their systems were present. The dataset contains AT&T customer records including full names, physical addresses, email addresses, phone numbers, dates of birth, US Social Security Numbers (encrypted), government-issued IDs, and account passcodes. The data is pipe-delimited and includes both current and billing address information for US consumers.
comelec.gov.ph
A breach of the Commission on Elections (COMELEC) of the Philippines, exposing the entire Philippine voter registration database. The archive contains voter registration records (new_id_released.txt, web_id_onhand.txt, web_id_disapproved.txt), overseas absentee voter data (overseas_absentee_all.txt, overseas_absentee_scratch.txt), geographic reference codes, embassy and country codes, web application user accounts with hashed passwords (dbadmin_usersinformation.txt), and internal system user accounts (fum_users.txt). The data includes full names, dates of birth, addresses, fingerprint data, voter identification numbers (VINs), passport numbers, and biometric information for millions of Filipino voters including overseas absentee voters.
zoosk.com
Breach of Zoosk, an online dating platform. The dataset contains records with registration/activity dates (spanning 2012–2015), usernames, email addresses, and MD5-hashed passwords. This data is consistent with the widely reported Zoosk breach that surfaced around 2020, containing approximately 30 million records originally collected from the platform.
Takoyaki
A SQL database dump containing user records with usernames, email addresses, SHA1-hashed passwords, and plaintext passwords. The dataset appears to be from a gaming or forum community platform. The name 'Takoyaki' likely refers to the platform or service breached. Contains approximately thousands of records based on file size.
ssndob.cc
Web server access logs from SSNDOB (ssndob.cc), an underground marketplace that sold Social Security Numbers and dates of birth of US individuals. The logs dated February 23, 2014 capture HTTP requests including login and registration events with plaintext credentials visible in POST request logs. SSNDOB was a cybercriminal service that traded in PII including SSNs, DOBs, and other personal data on millions of Americans.
soulsplit.net
User credential dump from SoulSplit, a RuneScape private server (RSPS). Contains usernames, email addresses (many using placeholder 'none@none.com'), and SHA1 password hashes. Data is consistent with a game account database leak from an RSPS community.
Threat briefings
What our analysts are tracking.
Original reporting on emerging breaches, leak campaigns, and the operators behind them. No press releases. No reposts.
Threat brief
Plaintext credentials from ys168.com surface in a Chinese-language dump
A plaintext credential dump from ys168.com, a Chinese file-hosting service, is being shared on BreachForums. The archive contains around 657,000 records of usernames, plaintext pas…
Threat brief
An expanded Elance archive resurfaces with 2.6M user records and admin accounts
A new variant of the Elance breach archive is being shared on BreachForums. Elance was the early freelance-work marketplace that eventually merged into what became Upwork, and this…
Threat brief
Havenly database dump exposes 1.7M interior-design-platform accounts
A MySQL database dump and customer CSV from Havenly, the Denver-based online interior-design platform, is circulating on dark-web forums. The combined data covers roughly 1.7 milli…
Who uses it
Built for the teams defending exposed identities.
Surface credential exposure across your domain. Pivot from a single leaked email to every dataset that record appears in, then push remediation to your IDP in seconds.
Detect compromised customer accounts before they're exploited. Score session and signup risk against known-stolen credentials joined to identity attributes.
Hit the API from your own infrastructure. Boolean queries, cursor pagination, sparse fields. Same query language as the UI, free for the first 500 calls a day.
For engineers
Wire exposure data into your stack.
Same engine that powers this site, exposed as a clean REST API. Boolean queries. Cursor pagination. Sparse fields. HATEOAS links. Free for the first 500 calls a day, with quota tiers for production traffic.