Meta Pixel
Security EducationSeptember 3, 202610 min read

Leak Websites: Where Stolen Data Ends Up, and How to Check If Yours Is There

A leak website is anywhere stolen data gets published: a ransomware gang’s extortion page on Tor, a hacking forum, a Telegram channel, a paste site. You do not need to visit any of them to find out whether your data is there. This is what each kind of site is, what happens to a record after it lands on one, and how to check from your own browser in a few seconds.

By LeakNix

The short version

  • Stolen data ends up in four kinds of place: ransomware leak sites, hacking forums, Telegram and combolist dumps, and paste sites or exposed servers.
  • Whatever is posted gets copied, merged and resold within days. Once it is public it stays public.
  • Services like Have I Been Pwned and LeakCheck collect what is posted and index it by email address. That is what a “dark web scan” actually is: a lookup in those indexes, not a live crawl.
  • So the way to find out if you are on a leak site is to look up your email address, not to go looking on Tor.

The four kinds of leak site

1. Ransomware leak sites

When a ransomware group breaks into a company, it now steals the data before encrypting anything. If the company will not pay, the group publishes the data on its own site, usually a Tor .onion address, with a countdown clock. The Maze group started this “double extortion” in late 2019 and every major group since has copied it. Cl0p used it at scale in 2023 after exploiting the MOVEit file-transfer software, posting data from hundreds of organizations. LockBit ran the busiest site of all until law enforcement seized it in February 2024.

What ends up here is corporate data: HR files, customer databases, contracts, scans of passports sent to an HR department. If your employer, your hospital, your school or your bank’s software supplier was hit, your details are in the dump as collateral. You were never the target. You are in the spreadsheet.

2. Hacking forums

This is usually what people mean by a “leaks website”. RaidForums was the main marketplace for stolen databases until the FBI and Europol seized it in April 2022. BreachForums replaced it within weeks; its founder was arrested in March 2023, the site has been seized and relaunched more than once since, and something with that name is usually online. Databases are sold there, or given away for forum credits, or dumped free to build a reputation. The 2021 Facebook scrape of 533 million phone numbers went from a paid product to a free download on one of these forums, which is why it is in every index now.

Forums are also where breaches get announced before the company admits them. A post saying “selling 560M Ticketmaster records” appeared on BreachForums in May 2024, weeks before Ticketmaster confirmed a breach.

3. Telegram channels and combolist dumps

Telegram has quietly become the biggest distribution channel for stolen logins. Channels post “cloud logs”, the output of infostealer malware that copies saved passwords and cookies out of infected browsers, in files of millions of lines at a time, free for a taste and paid for the full feed. Other channels post combolists: email:password pairs collected from many breaches and cleaned up for automated login attempts. In early 2025 Have I Been Pwned loaded a corpus from these channels called ALIEN TXTBASE with 23 billion rows in it. Nothing here is behind Tor. It is an app on your phone.

4. Paste sites and exposed servers

Pastebin and its clones are where small dumps and samples get posted, often as proof before a sale. Separately, a great deal of data leaks without any hacker at all: a company leaves a cloud storage bucket or a database server open to the internet with no password, and a researcher, or someone less polite, finds it. The 2019 exposure of a People Data Labs server with 1.2 billion enriched profiles was that kind of leak. These are not “leak sites” in the sense of someone publishing, but the data ends up in the same indexes.

What happens to your record after it is posted

The life cycle is consistent. A database is sold privately first, to a few buyers, for real money. After weeks or months it is resold cheaper, then leaked free by someone who bought it and wants credit, then merged into combolists with everything else. By the time it reaches an index like HIBP it has usually been copied hundreds of times. There is no taking it back and no one to ask.

The three things that get done with it:

  • Credential stuffing. Tools take every email:password pair and try it against Netflix, PayPal, Amazon, every bank, every airline. It works because people reuse passwords. The 2023 23andMe breach was not a hack of 23andMe’s systems; it was about 14,000 accounts logged into with passwords reused from other leaks, and from those accounts the attackers scraped the relatives data of roughly 6.9 million people.
  • Targeted phishing. A message that knows your name, your old password and the service it came from is far more convincing than a generic one. The extortion emails that quote a real password of yours are this, done cheaply.
  • Identity fraud. Where the dump includes dates of birth, addresses and government ID numbers, it feeds loan applications, SIM swaps and account recovery attacks. The 2024 National Public Data leak put hundreds of millions of Social Security numbers into circulation; the company filed for bankruptcy shortly after.

Should you go and look yourself?

No, and not for the reason you might expect. It is not especially dangerous to open Tor Browser. It is pointless. The forums require registration and often a fee to download anything. The ransomware sites post multi-gigabyte archives, not searchable lists. The Telegram feeds are millions of lines a day. You cannot search 10 billion records by scrolling, and downloading a stolen database to grep it for your own name puts a copy of everyone else’s data on your computer, which in most places is somewhere between unwise and illegal.

Other people have already done the collecting. Use them.

How breach indexes work, and what a “dark web scan” really is

Have I Been Pwned, run by Troy Hunt since 2013, collects breach data as it becomes public, verifies it, and indexes it by email address. As of September 2026 it lists 1,034 breached sites and about 17.8 billion breached accounts. LeakCheck does the same job commercially with a wider net; it indexes around 10 billion records, including stealer logs, and unlike HIBP it stores the password that sat next to each address.

Almost every consumer “dark web scan”, including ours, is a lookup in indexes like these. Nobody is crawling Tor on your behalf when you press the button. The phrase is marketing for “we check the breach databases”, which is the right thing to do, and would be more persuasive if more companies said so plainly.

What the indexes cover well: anything that has been posted publicly or traded widely enough to be collected. What they miss: data still being sold privately, dumps from the last few days, and anything not keyed to your email address, such as a file of names and Social Security numbers with no email column. A clean result means nothing found in what has been indexed. It does not mean nothing exists.

How to check

  1. Type your email address on LeakNix. It is looked up in both LeakCheck and HIBP, the results are merged, and duplicates are removed. The free result shows the breaches, one leaked password partly masked, and the other fields exposed. The full report, a one-off $28.95, shows every password in full.
  2. Check any other addresses you have used: old work addresses, the one from university, the one you give to shops.
  3. If you want a second opinion, check HIBP directly. It is free and it is one of our two sources; it will not show the passwords.
  4. Turn on the breach alerts in your password manager or browser so the routine checking happens without you.

You are on a leak site. Now what

It depends on what leaked. Work through whichever of these apply.

A password

Change it everywhere it was used, email account first. Add a passkey or an authenticator app to the important accounts. The password leak guide has the full order of operations.

A phone number

Expect scam texts and calls that use your name. Set a port-out PIN with your carrier so the number cannot be moved to a new SIM by someone who knows your details. Stop using SMS as your only second factor on anything that matters.

A Social Security number or ID document

Freeze your credit at Equifax, Experian and TransUnion. It has been free by federal law since 2018 and takes ten minutes each. Get an Identity Protection PIN from the IRS so nobody files a return in your name. Outside the US, the equivalent is your national credit bureau’s fraud alert.

Name, address, date of birth

On their own these are mostly a phishing risk: the messages get more convincing. They also sit on data broker sites that republish them for anyone to search, which you can do something about. See data removal services.

Questions people ask

Can I get my data taken off a leak site?

Not from a ransomware site or a forum; there is nobody to ask and the data has already been copied. What you can remove is your data from the legal data brokers, the people-search sites that compile addresses and phone numbers and sell them. That is a different problem and it is solvable.

Is it illegal to look at a leak site?

Reading a page generally is not, in most countries. Downloading a stolen database, or using anything in it to access an account, can be. This is not legal advice, and the practical answer is the same either way: you gain nothing by going there that an index lookup does not give you.

Why does my email show up in a breach of a company I have never heard of?

Usually because that company had your data anyway. Data brokers, marketing platforms and analytics firms hold profiles on people who never signed up with them. Sometimes a service you did use was white-labeled from a supplier you never saw. And sometimes the index attributes a combolist to a name that is not really a company at all.

Is dark web monitoring worth paying for?

Sometimes. What you are paying for is someone re-running the lookup and emailing you when a new dump includes you, which a password manager does for free for passwords. Where it earns its fee is monitoring things a password manager does not, like your Social Security number, and bundling it with identity restoration insurance. The monitoring comparison and the explainer go into which is which.

Find out if you are in the dumps

The lookup takes a few seconds, needs no account, and covers both LeakCheck and Have I Been Pwned.