# A leak alert arrived. Find what needs a closer look.

[A leak alert arrived. Find what needs a closer look.](https://leakradar.io/en/use-cases/incident-response)

Reviewed: 2026-09-09

Investigate reported credential exposure, identify the associated accounts and services, and prepare findings for the team handling the response.

Create a free account to start investigating.

## The alert rarely tells the whole story.

An exposed address may relate to a historical record, a third-party service or an account that has changed. Investigate the available context before deciding how it relates to the event your team is handling.

Connect the leak record to your own evidence.

## From an alert to an informed handoff

### Start with the indicator

Sign in and search the email or domain from the alert using the appropriate mode.

### Establish the context

Examine the service, source and available dates. Compare the findings with your organization's own records.

### Prepare the follow-up

Export useful material, pass it to the response team and configure monitoring where continued visibility is needed.

## What you can work with

### Targeted investigation

Move from a reported address or domain to the matching records available in LeakRadar.

### Evidence for responders

Use exports and domain reports to support investigation notes and communication with the responsible team.

### Monitoring after review

Keep relevant domains or addresses under observation after the initial investigation.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

Illustration with fictional data.

## Before you get started

### Does LeakRadar reset passwords or revoke sessions?

No. Your team applies account and device remediation in its own systems. LeakRadar supplies data to support those decisions.

### Does a newly found record mean a new compromise?

Not necessarily. Discovery or indexing time is not the time of compromise. Compare the available source context with your own logs.

## Give the response team more context.

Open the member area to examine the indicator behind your alert.

## The data behind LeakRadar

Investigate exposed accounts across stealer logs, combolists, raw leak files and dark web forums. Inspect plaintext passwords when available in the source.

639,979,587,084 lines across indexed leak files. File lines, not a count of unique accounts.

Updated: 2026-09-10T04:57:18.349Z

## Explore the source behind a match

### Stealer logs

Connect a captured login to its service URL, username and password to understand which access is exposed.

[API documentation](https://docs.leakradar.io/#tag/Search-Email)

### Combolists

Find email/password and username/password pairs, including records without a service URL.

[API documentation](https://docs.leakradar.io/#tag/Search-Combolists)

### Raw leak files

Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.

[API documentation](https://docs.leakradar.io/#tag/Raw-Search)

### Dark web forums

Search indexed forum posts for mentions of your organization and examine the discussion's source context.

[API documentation](https://docs.leakradar.io/#tag/Dark-Web-Search)

## Plaintext passwords, with their account context

Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.

Compare plans for plaintext access and included unlock points.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

## Sources and access

- [How our data is organized](https://leakradar.io/en/methodology)
- [Trust center](https://leakradar.io/en/trust)
- [Alternatives](https://leakradar.io/en/alternatives)
- [Compare plans](https://leakradar.io/en/#pricing-plans)
