OSINT Data Breach Search: What Leaked and Where
An OSINT data breach search starts the moment someone tells you your data is for sale: a ransom note, a journalist's email, a screenshot from a forum. We find the listing, work out what it contains and who is behind it, and give your lawyers evidence they can act on.
- Is the data really out?
- Where is it offered?
- What does it contain?
- Who is selling it?
An OSINT data breach search is a one-off investigation after a suspected leak. Analysts locate where your data is advertised or published, capture the evidence, compare samples and file listings with your own records, trace the likely source system or supplier, and profile the seller. We observe and document; we never buy the data. Notification decisions stay with you and your counsel.
Four Questions an OSINT Data Breach Search Answers
Is it out, where is it, what is in it, and who has it. Each answer changes a different decision: notification, containment, remediation or law enforcement contact.
| Question | What we check | Decision it supports |
|---|---|---|
| Is our data really out? | Listings, posts and samples that name you or match your records | Whether you have a breach to manage at all |
| Where is it offered? | First appearance and reposts across forums, markets, leak sites and channels | How widely it has spread, and which hosts can receive takedown requests |
| What does it contain? | Record counts, column names, file trees and sample rows, compared with your systems | Which people, contracts and regulators are affected |
| Who is selling? | Handle history, past listings, reputation and links to known groups | Whether more data is likely to surface, and what to give law enforcement |
How a Leak Investigation Runs
We confirm the claim, capture the evidence, validate the content against your records, trace the source and then keep watching for reposts.
- Brief and preserveYou send what you have: screenshot, ransom note or URL. We agree scope and who receives findings, usually counsel.
- Locate and captureWe find the original listing and its copies and capture pages, timestamps and handles with hashes so the record holds up later.
- Validate without buyingFree samples, screenshots and directory listings published by the seller are compared with your records. Your team confirms matches internally; we never pay for proof.
- Trace the sourceField names, file paths and date ranges usually point to a system or a supplier. Third parties were involved in 48% of breaches in Verizon's 2026 report, so we check suppliers early.
- Profile the sellerHandle history, previous sales, links to other personas, and how credible the actor's past claims have been.
- Report and watchA written report with evidence, confidence levels and next steps, then monitoring for reposts, price drops and new samples.
Fresh Breach, Recycled Dump or Fake Claim?
Many advertised leaks are old data repackaged or exaggerated. Telling them apart early changes what you notify.
Signs that point to a new breach:
- Records or documents dated after your last known incident, or internal file paths that never left your network.
- Columns that match one specific system, such as a CRM export or HR platform, rather than a mix of sources.
Signs of a recycled or inflated listing:
- Samples that match an older public breach or a combo list already circulating.
- Record counts far larger than your customer base, or email domains that are not yours.
If the data turns out to be mostly passwords and session cookies, the problem is usually infostealer infections, not a database breach; see leaked credential and stealer log monitoring. If a ransomware group has named you, ransomware leak site monitoring covers the countdown and publication.
Breach Notification Deadlines Are Your Legal Duty
Notification clocks belong to you as controller or registrant, not to us. Our findings feed the decision your counsel makes, and we work to their timetable.
| Rule | Trigger | Deadline |
|---|---|---|
| GDPR Article 33 (EU) | Personal data breach, unless unlikely to result in a risk to individuals | Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware; a processor must tell the controller without undue delay (Art. 33) |
| GDPR Article 34 (EU) | Breach likely to result in a high risk to individuals | Tell the affected people without undue delay (Art. 34) |
| SEC Form 8-K, Item 1.05 (US public companies) | Cybersecurity incident the company determines to be material | Generally four business days after the materiality determination, with a narrow delay if the US Attorney General finds a substantial risk to national security or public safety (SEC, July 2023) |
US state breach laws, sector rules and contracts may also apply. Because the GDPR clock runs from awareness, a listing we find can itself start it, so agree with counsel who receives findings and when. Our evidence answers what regulators ask: what data, how many people, since when. Teams that combine this with containment work often bring in OSINT for incident response.
What We Will Not Do During an OSINT Leak Investigation
We do not buy your data back, negotiate with sellers, download full dumps of other people's data or log in to anything with stolen credentials.
- No purchases. Paying a seller funds the crime, does not delete copies and can create legal exposure. We validate from what is published or offered as a free sample.
- No negotiation. Extortion contact is for you, your counsel and specialist negotiators; we do not pose as a buyer.
- Minimal handling of personal data. We capture what proves the leak and its scope, not full copies of customer or employee records.
- No hack-back. We do not access seller infrastructure or log in with stolen credentials.
What You Receive and How Fast
A confirmation answer first, then a full report on content, source and seller, with urgent delivery available when a deadline is running.
A first answer to "is it really out there?" is often a small task we can sometimes return within a business day. A full investigation of contents, source and seller is a focused piece of work from 10 business days, quoted at a fixed price after written scoping; urgent delivery costs 50% more, and the fee goes down if we miss the agreed date. Every report is reviewed by a senior analyst and covered by confidentiality or an NDA.
The report sets out each listing with captures, what the data contains and whom it affects, the likely source with a confidence level, a seller profile, takedown options and a watchlist for reposts. Breach work is one of our OSINT services for security and legal teams; law firms running the response often use it alongside their own work for clients (OSINT for law firms).
Tell Us What You Have Seen
Send the screenshot, link or ransom note and your notification constraints. We will confirm scope and the fastest way to an answer.
OSINT Data Breach Investigation FAQ
A customer forwarded us a forum post claiming to sell our user database — can an OSINT data breach search tell us quickly whether the leak is real before we start notifying people?
Yes, that is the first thing we establish. An OSINT data breach search locates the original post and any copies, captures them, and compares the seller's free samples, column names and record counts with your systems. Your team confirms matches internally. Often the answer is clear within a business day: a fresh breach, an old dump repackaged, or a claim with nothing checkable behind it.
Our lawyer says the GDPR 72-hour clock may already be running — will your investigation be finished in time, and who is actually responsible for notifying the regulator?
You are, as the controller. GDPR Article 33 requires notification without undue delay and, where feasible, within 72 hours of becoming aware, and a late notice must give reasons for the delay (Art. 33). Our findings support that decision but do not set the deadline. We agree with counsel up front who receives findings, send the confirmation answer first and the full report later, so you can notify on what is known and update afterwards.
We're a listed US company and a ransomware group posted our name — does an OSINT leak investigation help with the SEC Form 8-K materiality decision, or is that separate?
It feeds that decision but does not make it. Under Item 1.05, a material cybersecurity incident is generally disclosed within four business days after the company determines it is material (SEC). Materiality is a judgment for management and counsel. What we add is evidence on what the group published, what the files contain, whether the claim matches your systems and whether more is likely, which helps them judge scope and impact.
The seller is offering to send us the full dataset if we pay a small fee to prove it is real — would you buy it on our behalf so we can see exactly what was taken?
No. We do not buy stolen data, even as proof. Payment funds the seller, does not remove copies and can expose you legally. We validate from free samples, screenshots and file listings the seller publishes, and your team checks them against your records. If you are considering any contact with the seller, that is a decision for you, your counsel and specialist negotiators.
We think the leak came from one of our payroll suppliers rather than our own systems — can you work out which company the data actually came from?
Often, yes, with a stated confidence level. Field names, export formats, file paths, date ranges and the mix of records usually point to a particular system or SaaS tenant, and that can match one supplier rather than you. Supplier involvement is common: Verizon's 2026 report found third parties involved in 48% of breaches (Verizon DBIR 2026). The report sets out the evidence so you can raise it with the supplier under your contract.
Once the investigation is over, how would we know if our leaked files get reposted on another forum or channel next month, and is that included or a separate service?
Watching for reposts is part of the close-out: the report includes a watchlist of handles, file names and phrases, and a short follow-on watch can be agreed in the same scope. If you want it to continue, it moves into ongoing dark web monitoring on our analyst-reviewed platform, which updates hourly.
Sources and Notes
- GDPR Article 33: notification to the supervisory authority
- GDPR Article 34: communication to the data subject
- SEC: cybersecurity disclosure rules, Form 8-K Item 1.05 (July 2023)
- Verizon: 2026 Data Breach Investigations Report
Sources checked 8 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.