01

Breached credentials

Search a single identifier across our credential records. Each match carries the source it was recovered from and the month that source is dated to, plus the first and last time the identifier appears anywhere in the index.

Where breached credentials come from

A service is compromised and its user table is taken - published to make a point, sold, or circulated privately for years before either. What reaches an index like this one is whatever survived that journey.

Almost nothing arrives clean: dumps get merged, deduplicated, renamed, split, and resold, so the same row appears in a dozen compilations under a dozen names. That is why a match carries the source it was recovered from and the date it is dated to, rather than one authoritative breach date it cannot honestly claim.

What a credential row can and cannot tell you

One row is one identifier as one source held it: evidence the pair was exposed at least once. It is not proof the password still works, nor a claim about which company leaked it - a compilation often names no origin at all.

Fields a source never held come back as empty strings, not missing keys, so every row has the same shape and an absent value is one you can check for. Free returns every row with the credentials withheld, five a week unlockable in full; Pro and above return the values on every row.

Why one address appears many times

An email address that has been through ten years of the internet is usually in more than one of these. Each appearance is a separate row from a separate source - and that spread across sources and dates is what tells you whether an exposure is old news or last month.

The result carries the first and last time the identifier appears anywhere in the index, so that spread is a figure you can read rather than something you assemble by hand.

What a query returns.

One record is a single row recovered from one breached source, carrying whichever identifiers that source held.

Query by
email, username, password, full_name, ip_address, phone_number, hash, domain
Each match carries
source.name, source.date
Across the whole result
found, databases, first_seen, last_seen
Reachable by
API key or dashboard

Standing monitors watch one asset or an entire domain and notify you when it next appears.

InfoBreach

Start with one identifier.

Free runs 25 searches a day across breach and device records, and 25 each for people search and social. Withheld rows unlock five a week, or a paid plan reveals them outright.

Not ready for an account? Check one identifier with no signup. The demo returns a masked sample of what the indexes found.