Intelligence Lookup

See what an attacker can find about you.

Enter your email. We show you which breaches you're in, what leaked, and how to lock it down, with proof for every finding. We only ever check your own address.

your own address only · we never show the stolen data · we never see your password

Why this matters

Your data is already sitting in breaches like these.

2013
3B
accounts
Yahoo
Credential compromise

Every account the company had, disclosed years after the fact.

EmailsPhone numbersDates of birthHashed passwordsSecurity questions
2024
2.9B
records
National Public Data
Vendor or third party

A data broker nobody signed up for put identity records into open circulation.

NamesSocial Security numbersAddressesPhone numbers
2021Indonesia
279M
records
BPJS Kesehatan
Undisclosed

Indonesia's health insurance database appeared for sale on a hacking forum.

National ID (NIK)NamesAddressesPhone numbersFamily records
2018
1.1B
records
Aadhaar
Exposed API

India's national ID system was reachable through an endpoint that never checked who was asking.

National ID numbersNamesAddressesBiometric references
2019
885M
documents
First American Financial
Broken access control

Property documents were reachable by changing a number in the URL. No login required.

Bank account numbersMortgage recordsTax recordsSignatures
2021
700M
profiles
LinkedIn
Scraping

Profile data pulled at scale through public surfaces, then packaged for sale.

NamesEmailsPhone numbersJob historyLocations
2024
560M
customers
Ticketmaster
Credential compromise

A cloud data warehouse reached with stolen credentials and no second factor.

NamesAddressesPhone numbersPartial payment cards
2021
533M
users
Facebook
Scraping

Phone numbers tied to real names, published in full on a forum.

Phone numbersNamesLocationsRelationship status
2018
500M
guests
Marriott
Undetected intrusion

Four years inside the reservation system before anyone noticed.

NamesAddressesPassport numbersSome payment cards
2020
250M
support records
Microsoft
Misconfiguration

A misconfigured database left years of support logs readable by anyone who looked.

EmailsIP addressesSupport case details
2023
200M
accounts
Twitter / X
Exposed API

An API let anyone match an email address to the account behind it, in bulk.

EmailsUsernamesDisplay names
2024
190M
people
Change Healthcare
Ransomware

A ransomware attack on a medical payments processor, at national scale.

Health recordsBilling dataInsurance detailsSome SSNs
2013
153M
accounts
Adobe
Undetected intrusion

Password hints shipped alongside the encrypted passwords they hinted at.

EmailsEncrypted passwordsPassword hints
2017
147M
people
Equifax
Unpatched software

One unpatched web server exposed the credit data of half a country.

NamesSocial Security numbersDates of birthAddresses
2013
110M
customers
Target
Vendor or third party

Stolen credentials from an air-conditioning vendor, during the holidays.

Payment cardsNamesAddressesPhone numbers
2019
106M
applicants
Capital One
Misconfiguration

A cloud firewall rule let an outsider reach internal storage from the internet.

NamesAddressesCredit scoresSome SSNsBank account numbers
2020Indonesia
91M
accounts
Tokopedia
Undisclosed

One of Indonesia's largest marketplaces, traded openly online.

NamesEmailsHashed passwordsDates of birth
2016
57M
riders and drivers
Uber
Credential compromise

Credentials left in a code repository, then a payment to keep it quiet.

NamesEmailsPhone numbersDriver licence numbers
2023Indonesia
1.5TB
of customer data
Bank Syariah Indonesia
Ransomware

A ransomware group published the lot after the bank refused to pay.

Contact detailsFinancial documentsCard informationPasswords
2023
6.9M
profiles
23andMe
Credential compromise

Reused passwords plus a relative-matching feature turned into a genetic data leak.

NamesAncestry resultsRelative matchesLocations
2025
1M+
log records
DeepSeek
Misconfiguration

An unauthenticated database exposed chat history and internal keys.

Chat historyAPI keysBackend details
2024Indonesia
210+
government services
National Data Center
Ransomware

Ransomware took down Indonesian public services for days. No usable backup.

Immigration systemsLicensingPublic service records
2021Indonesia
1.3M
people
Indonesian Health Ministry
Misconfiguration

The COVID test-and-trace app exposed health status alongside identity.

NamesID numbersTest resultsHealth status
Before and after

Your data is already out there. See it, then shut it.

Left, an attacker already has the breach dump. Right, you check your own verified address, see exactly what leaked, and close the biggest holes first.

your dataAttackerCheckedyour addressProvenwith evidenceLocked downa plain planBulwark
Before Bulwark

Your email and passwords sit in old breaches. An attacker buys the dump and walks into the accounts you reused them on.

After Bulwark

You check your own verified address, see proof of exactly what leaked, and work an ordered plan that closes the biggest holes first.

What you get

See where you're exposed, and how to fix it.

01 · What we find

Exactly where you're exposed.

We check your email against known breaches and public records. You see which breach, when it happened, and what leaked. We show that you were in it, never the stolen data itself.

02 · The fix

A guided plan, in plain words.

A short checklist that starts with the two steps that close most of your risk, plus a password check that runs inside your browser, so we never see the password you type.

How it works

Four steps, about five minutes.

No security knowledge needed, and nothing to install.

  1. 01

    Create an account

    We email you a 6-digit code. Typing it back proves the address is yours. That's the only reason we ask you to sign in.

  2. 02

    Run the lookup

    One click. We check your verified email against breach records and public sources. We use it for the check and never store it.

  3. 03

    Read the proof

    Which breach, when it happened, how many accounts it hit, and what leaked. Evidence you can check yourself, never the stolen data.

  4. 04

    Work the plan

    A short checklist, worst risk first. Saved to your history, so you can watch your exposure come down.

Why we ask you to sign in

We only check an address you've proved is yours.

Plenty of sites will look up anyone's data for you. That's surveillance sold as safety, and we won't build it. Signing in is how we know the address is yours: the whole difference between a personal tool and a people-search engine.

What we store

The result, not the data.

How many exposures, whether a password leaked, the risk level, and the date. Never the address you checked, never the leaked data. Delete your history any time from your account.

What we never do

Show you someone else's life.

No lookups on other people, ever. No reselling what we find. This only runs on an address you've proved is yours.

Pricing

Pay per lookup. No subscription.

One payment, one full check on your own address. Nothing recurring, and no card kept on file.

Free during early access
$2.99Rp 50.000

per lookup, paid once. No subscription, no card kept on file.

  • Your email checked against breaches and public records
  • Proof for every exposure we find
  • A simple fix plan, in plain words
  • A password check that runs in your browser, not on our servers
  • Your full history, deletable any time
Start a free lookup

Checkout isn't built yet, so lookups are free today and we ask for no card. The price above is what one will cost once it is.

FAQ

The questions people ask first.

Is this legal?

Yes. We check an address you've proved is yours against breaches and sources that are already public. No hacking, and we never look up anyone but you.

Why do I have to sign in first?

It's how we know the address is yours. A checkbox saying "this is mine" is a claim, not proof. Without it, this would be a people-search engine for other people's data, the one thing we won't build.

What do you actually store?

The result only: how many exposures, whether a password leaked, the risk level, and the date. Never the address you checked, never the leaked data. Delete it all in one click from your account.

Can you see the password I test?

No, by design. Your browser scrambles the password and sends only the first five characters of that scramble. The password never leaves the page, and we couldn't rebuild it.

Can I look up my partner's or company's email?

No. Only an address you've verified. Checking a second address you own yourself is coming, and it'll need the same proof.

What if nothing shows up?

Good news, read carefully: nothing turned up in the sources we can see, not that you were never exposed. Keep unique passwords and two-factor on anything that matters.

What happens after I fix things?

Run the lookup again any time. Each result is saved, so your history shows your exposure dropping as you work the plan.

Start here

Find out what an attacker already knows about you.

Create an account, verify your email, and run your first lookup in minutes.