An ethical hacker for everyone

Security that shows you the proof.

Most people and companies are already exposed and never hear about it. We find it, prove it with real evidence, and show you what to do next. No scare scores, and never someone else's data.

consent first · we never show the stolen data · we never see your password

Free with an account

Not sure where to start? Check your website.

A free check of what's costing you customers and search traffic, with the top fixes and a before/after of your homepage. It's also the easiest way to see how we work.

The risk

This already happened, to companies people trusted.

Real breaches, with what leaked and why. 5 of them are Indonesian. The data is still out there, which is why both sides of this product exist.

2013
3B
accounts
Yahoo
Credential compromise

Every account the company had, disclosed years after the fact.

EmailsPhone numbersDates of birthHashed passwordsSecurity questions
2024
2.9B
records
National Public Data
Vendor or third party

A data broker nobody signed up for put identity records into open circulation.

NamesSocial Security numbersAddressesPhone numbers
2021Indonesia
279M
records
BPJS Kesehatan
Undisclosed

Indonesia's health insurance database appeared for sale on a hacking forum.

National ID (NIK)NamesAddressesPhone numbersFamily records
2018
1.1B
records
Aadhaar
Exposed API

India's national ID system was reachable through an endpoint that never checked who was asking.

National ID numbersNamesAddressesBiometric references
2019
885M
documents
First American Financial
Broken access control

Property documents were reachable by changing a number in the URL. No login required.

Bank account numbersMortgage recordsTax recordsSignatures
2021
700M
profiles
LinkedIn
Scraping

Profile data pulled at scale through public surfaces, then packaged for sale.

NamesEmailsPhone numbersJob historyLocations
2024
560M
customers
Ticketmaster
Credential compromise

A cloud data warehouse reached with stolen credentials and no second factor.

NamesAddressesPhone numbersPartial payment cards
2021
533M
users
Facebook
Scraping

Phone numbers tied to real names, published in full on a forum.

Phone numbersNamesLocationsRelationship status
2018
500M
guests
Marriott
Undetected intrusion

Four years inside the reservation system before anyone noticed.

NamesAddressesPassport numbersSome payment cards
2020
250M
support records
Microsoft
Misconfiguration

A misconfigured database left years of support logs readable by anyone who looked.

EmailsIP addressesSupport case details
2023
200M
accounts
Twitter / X
Exposed API

An API let anyone match an email address to the account behind it, in bulk.

EmailsUsernamesDisplay names
2024
190M
people
Change Healthcare
Ransomware

A ransomware attack on a medical payments processor, at national scale.

Health recordsBilling dataInsurance detailsSome SSNs
2013
153M
accounts
Adobe
Undetected intrusion

Password hints shipped alongside the encrypted passwords they hinted at.

EmailsEncrypted passwordsPassword hints
2017
147M
people
Equifax
Unpatched software

One unpatched web server exposed the credit data of half a country.

NamesSocial Security numbersDates of birthAddresses
2013
110M
customers
Target
Vendor or third party

Stolen credentials from an air-conditioning vendor, during the holidays.

Payment cardsNamesAddressesPhone numbers
2019
106M
applicants
Capital One
Misconfiguration

A cloud firewall rule let an outsider reach internal storage from the internet.

NamesAddressesCredit scoresSome SSNsBank account numbers
2020Indonesia
91M
accounts
Tokopedia
Undisclosed

One of Indonesia's largest marketplaces, traded openly online.

NamesEmailsHashed passwordsDates of birth
2016
57M
riders and drivers
Uber
Credential compromise

Credentials left in a code repository, then a payment to keep it quiet.

NamesEmailsPhone numbersDriver licence numbers
2023Indonesia
1.5TB
of customer data
Bank Syariah Indonesia
Ransomware

A ransomware group published the lot after the bank refused to pay.

Contact detailsFinancial documentsCard informationPasswords
2023
6.9M
profiles
23andMe
Credential compromise

Reused passwords plus a relative-matching feature turned into a genetic data leak.

NamesAncestry resultsRelative matchesLocations
2025
1M+
log records
DeepSeek
Misconfiguration

An unauthenticated database exposed chat history and internal keys.

Chat historyAPI keysBackend details
2024Indonesia
210+
government services
National Data Center
Ransomware

Ransomware took down Indonesian public services for days. No usable backup.

Immigration systemsLicensingPublic service records
2021Indonesia
1.3M
people
Indonesian Health Ministry
Misconfiguration

The COVID test-and-trace app exposed health status alongside identity.

NamesID numbersTest resultsHealth status

Figures as publicly reported at disclosure. These count records, not people: a dataset can hold duplicates, which is why the BPJS figure exceeds Indonesia's population. Categories describe what leaked. We never show the leaked data itself.

How it works

From signed scope to a confirmed fix.

One path, whichever door you came through. Nothing runs until scope is agreed, every finding is proven, and we retest until it is closed.

Scopesigned authorizationDetectnon-destructiveReportgraded, with proofFixretested, closed
The line we will not cross

Consent is the whole product.

For individuals

Only an address you've proved you own.

Plenty of sites will look up anyone's data for you. That's surveillance sold as safety, and we won't build it. We store the result of a check, never the address, and you can delete it any time.

For business

Only systems you're allowed to test.

Nothing runs before you sign off on the scope. Production customer data stays out of scope. Findings go to you privately, published only with your written consent.

Start here

Which one are you?

Both start the same way: see what's already out there, with proof.