Data methodology
Reviewed
Where does the data come from?
LeakRadar indexes records and archives already shared publicly by third parties. Stealer Logs, Combolists and raw archives are separate datasets. Counts are not unique people and cannot be added to obtain a unique total.
Stealer logs
Connect a captured login to its service URL, username and password to understand which access is exposed.
Combolists
Find email/password and username/password pairs, including records without a service URL.
Raw leak files
Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.
Dark web forums
Search indexed forum posts for mentions of your organization and examine the discussion's source context.
Plaintext passwords, with their account context
Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.
Compare plans for plaintext access and included unlock points.
How are counts calculated?
Stealer Log counts are estimates. Matching records may be found even when a reliable volume estimate is unavailable.
lines across indexed leak files. File lines, not a count of unique accounts.
How are records grouped?
Groups are based on the URL domain and email domain. Both matching: same-domain addresses; URL only: other addresses using the domain; email only: domain addresses used elsewhere. These groups do not verify employment or a commercial relationship.
How should these reports be interpreted?
A domain in a credential record does not establish a breach of that domain’s servers, a valid password or the identity of the account owner.
Freshness and coverage limits
Indexing time is not the date of an intrusion. Public reports can be cached and do not provide a real-time detection guarantee. Blocklisted domains are excluded from publication. An empty result does not prove that an account is safe or that our sources cover every exposure.
Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.
Weekly reports describe records indexed during a stated UTC period, not the date an intrusion occurred. Raw-line totals exclude duplicate files, but do not prove that every line is unique. Volume bands are: below 100, 100 to 999, 1,000 to 9,999, and 10,000 or more records. They are not a risk score.