Breach & Dark Web Intelligence
Indicators that credentials or data appear in a breach dataset
DNA WEB reports whether an email, phone number, username or domain appears as an indicator in known breach datasets. We never expose credential contents — no plaintext passwords, no password lookups, ever.
What it finds
Signals this pillar surfaces
Breach indicators by email
Whether the identifier is present in a known breach dataset, which dataset, and roughly when it was recorded.
Breach indicators by phone or username
The same indicator approach extended to phone numbers and usernames where the provider supports it.
Domain-wide exposure
How many addresses on a monitored domain appear across breach datasets, useful for prioritising password resets.
Security exposure category
Every indicator is classified under the security-exposure category, separate from personal-data or impersonation findings.
How it works
From identifier to verified finding
- 01
Submit an identifier
Email, phone, username or domain, only for entities you are authorised to check.
- 02
Checked against breach datasets
The identifier is matched against indicator records from breach-intelligence sources — never against live credential contents.
- 03
Indicator, not content, is returned
You see that a match exists, the dataset name and approximate date — never the password or full record.
- 04
Recommended next step
A password-reset and monitoring recommendation is logged as a resolution option, not performed automatically.
What it is not
Boundaries we hold
- Not a password lookup — DNA WEB never displays credential contents, plaintext or otherwise.
- Not access to criminal marketplaces or paid dark-web forums — we use licensed, lawful breach-intelligence sources only.
- Not a claim that a match means an account is currently compromised — it means the indicator appeared in a dataset.
- Not automatic remediation — resetting credentials or notifying users remains your decision.