An ethical hacker for everyone

Security that shows you the proof.

Most people and most companies are already exposed and were never told. Bulwark finds it, proves it with documented evidence, and shows you exactly what to do next. Never a scare score, never someone else's data.

consent first · we never reveal the stolen data · we never see your password

The risk

This already happened, to companies people trusted.

Documented breaches, with what leaked and why. 5 of them are Indonesian. The data from all of them is still circulating, which is why both halves of this product exist.

2013
3B
accounts
Yahoo
Credential compromise

Every account the company had, disclosed years after the fact.

EmailsPhone numbersDates of birthHashed passwordsSecurity questions
2024
2.9B
records
National Public Data
Vendor or third party

A data broker nobody signed up for put identity records into open circulation.

NamesSocial Security numbersAddressesPhone numbers
2021Indonesia
279M
records
BPJS Kesehatan
Undisclosed

Indonesia's health insurance database appeared for sale on a hacking forum.

National ID (NIK)NamesAddressesPhone numbersFamily records
2018
1.1B
records
Aadhaar
Exposed API

India's national ID system was reachable through an endpoint that never checked who was asking.

National ID numbersNamesAddressesBiometric references
2019
885M
documents
First American Financial
Broken access control

Property documents were reachable by changing a number in the URL. No login required.

Bank account numbersMortgage recordsTax recordsSignatures
2021
700M
profiles
LinkedIn
Scraping

Profile data pulled at scale through public surfaces, then packaged for sale.

NamesEmailsPhone numbersJob historyLocations
2024
560M
customers
Ticketmaster
Credential compromise

A cloud data warehouse reached with stolen credentials and no second factor.

NamesAddressesPhone numbersPartial payment cards
2021
533M
users
Facebook
Scraping

Phone numbers tied to real names, published in full on a forum.

Phone numbersNamesLocationsRelationship status
2018
500M
guests
Marriott
Undetected intrusion

Four years inside the reservation system before anyone noticed.

NamesAddressesPassport numbersSome payment cards
2020
250M
support records
Microsoft
Misconfiguration

A misconfigured database left years of support logs readable by anyone who looked.

EmailsIP addressesSupport case details
2023
200M
accounts
Twitter / X
Exposed API

An API let anyone match an email address to the account behind it, in bulk.

EmailsUsernamesDisplay names
2024
190M
people
Change Healthcare
Ransomware

A ransomware attack on a medical payments processor, at national scale.

Health recordsBilling dataInsurance detailsSome SSNs
2013
153M
accounts
Adobe
Undetected intrusion

Password hints shipped alongside the encrypted passwords they hinted at.

EmailsEncrypted passwordsPassword hints
2017
147M
people
Equifax
Unpatched software

One unpatched web server exposed the credit data of half a country.

NamesSocial Security numbersDates of birthAddresses
2013
110M
customers
Target
Vendor or third party

Stolen credentials from an air-conditioning vendor, during the holidays.

Payment cardsNamesAddressesPhone numbers
2019
106M
applicants
Capital One
Misconfiguration

A cloud firewall rule let an outsider reach internal storage from the internet.

NamesAddressesCredit scoresSome SSNsBank account numbers
2020Indonesia
91M
accounts
Tokopedia
Undisclosed

One of Indonesia's largest marketplaces, traded openly online.

NamesEmailsHashed passwordsDates of birth
2016
57M
riders and drivers
Uber
Credential compromise

Credentials left in a code repository, then a payment to keep it quiet.

NamesEmailsPhone numbersDriver licence numbers
2023Indonesia
1.5TB
of customer data
Bank Syariah Indonesia
Ransomware

A ransomware group published the lot after the bank refused to pay.

Contact detailsFinancial documentsCard informationPasswords
2023
6.9M
profiles
23andMe
Credential compromise

Reused passwords plus a relative-matching feature turned into a genetic data leak.

NamesAncestry resultsRelative matchesLocations
2025
1M+
log records
DeepSeek
Misconfiguration

An unauthenticated database exposed chat history and internal keys.

Chat historyAPI keysBackend details
2024Indonesia
210+
government services
National Data Center
Ransomware

Ransomware took down Indonesian public services for days. No usable backup.

Immigration systemsLicensingPublic service records
2021Indonesia
1.3M
people
Indonesian Health Ministry
Misconfiguration

The COVID test-and-trace app exposed health status alongside identity.

NamesID numbersTest resultsHealth status

Figures as publicly reported at disclosure. These count records, not people: a dataset can hold duplicates, which is why the BPJS figure exceeds Indonesia's population. Categories describe what leaked. We never show the leaked data itself.

The line we will not cross

Consent is the whole product.

For individuals

Only an address you have proved you own.

Plenty of sites will look up anyone's leaked data for you. That is surveillance sold as safety, and we will not build it. We store the result of a check, never the address, and you can delete it any time.

For business

Only systems you have authorized us to test.

Nothing runs before scope is signed by someone empowered to grant it. Production customer data is out of scope. Findings go to you privately, and nothing is published without your written consent.

Start here

Which one are you?

Both start the same way: find out what is already out there, with proof you can check yourself.