Type an email address into a breach-checking tool and it will tell you, in seconds, whether that address has surfaced in a known data leak. That single fact — exposed / not exposed — is lawful, useful, and the honest edge of what open-source intelligence does with credentials. One step past it lies the criminal economy of combolists and infostealer logs, where the actual passwords are bought and sold. The distance between those two things is small technically and enormous legally. This briefing is a forensic map of email and credential exposure: what a leaked email or password legitimately reveals about a person or counterparty, exactly where the lawful line sits, and how exposed credentials feed a due-diligence risk picture without ever touching a stolen password.
TL;DR
Lawful credential OSINT works with the fact of exposure — which breaches an email appears in — not the passwords themselves. A breach-notification service (or our email-breach tool) reports exposure without revealing or storing passwords; that is open-source and generally lawful. Buying or using a combolist — the compiled email-password dumps traded on criminal channels — to obtain someone's actual password is unauthorised access and unlawful data processing, and for a regulated firm it carries the same GDPR/anti-bribery/AML exposure as any other stolen data. From an email alone, lawful OSINT can surface breach history, linked accounts, usernames, and profile images; it cannot lawfully surface a cleartext password, a live location, or private account contents. In due diligence, heavy exposure is a risk signal (weak opsec, account-takeover probability), corroborated against other evidence — never a stolen-credential shortcut. To check your own exposure safely: use your email address only, never your password, then rotate every affected password and turn on MFA.
What a leaked email actually exposes
An email address is an identity anchor. Once it is known, lawful open-source collection can build a surprising amount of context around it — all from the fact of its appearance in public sources, not from anyone's private data:
| Lawful (fact-of-exposure / public) | Unlawful (requires stolen data or access) |
|---|---|
| Which known breaches the address appears in | The cleartext or hashed password itself |
| Linked usernames and display names | Contents of the person's inbox or accounts |
| Accounts that exist on a platform (via public reset/enumeration signals) | Logging in to any of those accounts |
| Gravatar / public profile image | Live device or handset geolocation |
| Public mentions, posts, and registrations | Private phone, bank or passport records |
The left column is the raw material of a defensible investigation — every item is reconstructable by another analyst from the same public sources. The right column is what the criminal credential market sells, and it is the boundary this briefing is really about.
Breach exposure vs. the password itself: the line
Modern credential leakage comes from two engines. The first is the data breach: a service is compromised and its user table — emails, and often hashed or plaintext passwords — is stolen and eventually circulated. The second, now dominant, is the infostealer log: malware on an infected device silently harvests saved browser passwords, session cookies and autofill data, and uploads them to operators who bundle and sell them. Both feed the same downstream product: the combolist, a compiled file of credential pairs traded on criminal forums and Telegram.
A lawful breach-notification service ingests these corpora and exposes exactly one derived fact per query: does this email appear, and in which breach. It does not return the password. That design is the whole point — it lets a person or an investigator learn that exposure exists without redistributing the stolen secret. Crossing to the password itself — downloading the combolist, extracting the credential, testing it against a login — is the step from open-source intelligence into unauthorised access and unlawful data processing. Nothing about the ease of that step changes its legality.
Why the password is a trap even when it "works"
Analysts are sometimes tempted to "just confirm" an account by trying a leaked password. Beyond the illegality, it is bad tradecraft: a successful login is unauthorised access that taints the whole investigation and any evidence downstream; a failed one tells you nothing reliable (passwords rotate); and the mere possession of the combolist is itself the offence. A lawful investigation never needs the password — the fact of exposure, plus lawful corroboration, carries the analysis.
Why exposed credentials matter in due diligence
For a compliance or risk team assessing a counterparty, credential exposure is a signal, not a verdict. Read correctly, it contributes to a risk picture:
- Breadth of exposure. An entity whose key addresses appear across many breaches — especially infostealer logs, which imply a compromised device — has weaker operational security and a higher probability of account takeover and business-email-compromise.
- Recency. Fresh infostealer exposure is a live risk; a decade-old forum breach is largely historical.
- Role sensitivity. Exposure on an address used for banking, corporate email or a signing authority weighs more than a personal newsletter address.
- Corroboration. On its own it proves nothing about the counterparty's integrity. It is one input, weighed against corporate records, sanctions exposure and behaviour — the same discipline our due-diligence and digital-exposure work applies to every signal.
Crucially, all of this is assessed from lawful breach-notification data. The moment an investigation reaches for the actual leaked passwords, it stops being diligence and becomes the liability described in our probiv briefing: unlawfully-sourced personal data that engages GDPR Article 6, anti-bribery, and AML obligations for the firm that ingests it.
How to check your own exposure — safely
The most common question behind a search for "email password leak" is personal: am I exposed? The safe procedure:
Self-check, in order
- Check with your email address only. Use a reputable breach-notification service or our email-breach checker. A legitimate check never asks for your password — if a site does, leave.
- Rotate every affected password. Treat any account that shared a breached password as already compromised, and change it there too.
- Stop reusing passwords. Adopt a password manager so every account has a unique credential; one breach then can't cascade.
- Turn on multi-factor authentication everywhere it is offered — it defeats most credential-stuffing even when a password leaks.
- Watch for infostealer signs. If fresh exposure keeps appearing, assume a device is infected: run a reputable scan and consider the device compromised until cleaned.
For a person under elevated risk — a journalist, executive, or high-net-worth individual — reducing the exposed surface is its own discipline; our digital-footprint reduction guide covers the defender's playbook end to end.
What this method cannot do
A breach check confirms exposure, not safety: absence from known corpora does not mean an address is uncompromised, only that it has not surfaced in indexed leaks. Exposure does not reveal what a password was, and lawful OSINT will not tell you. And credential exposure alone characterises opsec risk, not a person's conduct or intent — reading it as proof of wrongdoing is an analytical error. It is a signal to weigh, never a conclusion to state.
Methodology & sourcing discipline
This explainer describes lawful breach-exposure collection only. It provides no combolist, infostealer log, or credential source, and no method for obtaining or using leaked passwords. In our own work, credential exposure is read from lawful breach-notification data, contributes as one confidence-tagged signal among many, and is never sourced from purchased credential dumps. Legal points are stated as they apply to regulated users; confirm with counsel for any specific matter.
Companion reading
- Probiv: Inside Russia's Leaked-Data Economy — the unlawful credential-and-data market this briefing draws the line against.
- Username OSINT: Trace a Person Across Platforms — the sister method: from an email or handle to a person, done defensibly.
- 5 Steps to Reduce Your Digital Footprint — the defender's side: shrink your exposed surface.
- Dark Web Threat Landscape 2026 — where breach and combolist markets sit in the wider picture.
Sources and further reading
- Have I Been Pwned — the reference breach-notification service and the model for lawful exposure checking (reports exposure, not passwords): haveibeenpwned.com.
- Our free email-breach checker — lawful exposure lookup by email address.
- GDPR (Regulation (EU) 2016/679), Articles 5 and 6 — lawful basis for processing personal data, including breach-derived data, in a regulated file; consult counsel.
- Guidance from national CERTs and data-protection authorities on infostealer malware and credential hygiene.
Assessing a counterparty's exposure — or your own — and want it done lawfully?
Our digital-exposure and due-diligence engagements read credential and breach exposure as a confidence-tagged risk signal, corroborated against corporate, sanctions and behavioural evidence — and sourced only from lawful breach-notification data, never from purchased dumps. Usable in a compliance file or a board decision.
Request an Exposure Assessment