IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
LeakData launches breach index with 1,485 incidents

LeakData launches breach index with 1,485 incidents

Mon, 27th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

LeakData has launched a publicly searchable English-language breach index listing 1,485 incidents.

Operated by CyberVisir Solutions, the service marks 1,068 of those incidents as verified. It also places a prominent caveat on its headline total of 18,662,888,724 affected-account records, saying the figure should not be treated as a count of unique people, users, or accounts.

That distinction is central to the launch. LeakData notes that the same identifier can appear in more than one incident, while organisations and data sources use different counting methods, with some reporting records and others reporting accounts.

Rather than combining numbers into what it describes as a misleading victim count, the site presents source-reported totals alongside labels for verification status and incident context. The directory can be searched without creating an account.

Each entry is intended to provide more detail than a breach name and a headline figure. Depending on the available evidence, records may include the breach or incident date, the date the item was added, affected-account figures, exposed data classes, severity, verification state, source context, and an English description.

The public index separates verified and unverified records. LeakData says verification is a record-level label and does not mean every source figure is complete or that all affected identifiers are unique.

How it works

LeakData presents the directory as a tool for readers who want to inspect the underlying context of breach reports. Its methodology places provenance, dates, verification state, and correction context alongside the breach data itself.

The operator also notes that coverage is not exhaustive. Some incidents may never become publicly verifiable, particularly older events or those handled privately.

Beyond the directory, the service includes a password-exposure check that uses a k-anonymous lookup design. According to LeakData, the full password is not sent as the lookup value during a check.

The approach is intended to reduce disclosure during the search process, though it is not a substitute for changing an exposed password, enabling multi-factor authentication, or reviewing account recovery settings.

LeakData also offers email and domain monitoring for authorised users. These features include plan-dependent risk notifications, API access, and signed webhook options, while domain monitoring is limited to domains a user is authorised to monitor.

Practical focus

The directory is framed around practical questions for security teams and affected users. These include what event is being described, when it occurred, which data types were reportedly exposed, what evidence supports a verification label, whether totals represent records, accounts, or known unique people, and what limitations exist in the available sources.

That focus reflects a broader issue in breach reporting, where very large figures can circulate widely without a clear explanation of what is being counted. By labelling source context and verification state, LeakData aims to make those limits visible in the public record.

Public documentation, privacy information, and acceptable-use terms also describe how the service is meant to be used. Monitoring and integration tools depend on the selected plan and on authorisation requirements.

CyberVisir Solutions, the service operator, is registered in England and Wales. The site is available in English and also offers a Turkish-language interface.

At launch, the public index shows 1,485 incidents, 1,068 of them marked as verified, while the summed source-reported total stands at 18,662,888,724 records without claiming that figure represents unique victims.