Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026

    The OSINT Newsletter – Issue #118

    August 11, 2026

    Mozilla updates GPG signing key for Firefox releases after exposure

    August 11, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»The OSINT Newsletter – Issue #118
    News

    The OSINT Newsletter – Issue #118

    adminBy adminAugust 11, 2026No Comments8 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    👋 Welcome to OSINT Tool Tuesday. This week we’re looking at Library of Leaks; a web-based search engine that indexes hundreds of publicly available breach and leak datasets so you can search masses of exposed records from a single, simple interface. No command line, no software installation, and no account setup required – you can simply search and go.

    🚨 This tool has been added to the OSINT Resources for Open Directories page on The OSINT Newsletter for easy reference later. That list serves as a roadmap for new tutorials in the future. If there are any tools you’d like to see added to the list and covered, please reach out to jake@osint.news with details.

    🪃 If you missed the last newsletter, here’s a link to catch up.

    ⚡ Everything Must Go (Including Their OPSEC): OSINT on eCommerce and Marketplace

    The OSINT Newsletter - Issue #117

    The OSINT Newsletter – Issue #117

    🎙️ If you prefer to listen, here’s a link to the podcast instead.

    Episode 22: Reply Guys and Robot Toolsmiths: Mining Forums for Long-Term History and Building an OSINT Tool That Improves Itself

    Episode 22: Reply Guys and Robot Toolsmiths: Mining Forums for Long-Term History and Building an OSINT Tool That Improves Itself

    Let’s get started. ⬇️

    Library of Leaks is a free online search platform that enables investigators to query hundreds of publicly indexed breach collections from a single website. Instead of hosting the leaks itself, it points you toward known sources across the OSINT ecosystem.

    🎩 H/T: Distributed Denial of Secrets

    The platform is particularly useful during the reconnaissance phase of an investigation when you’re trying to establish whether an individual, organisation or identifier has previously appeared within publicly available breach data.

    Important Note: The presence of information within a breach dataset should never be interpreted as evidence of current compromise or wrongdoing. Many datasets are historical, duplicated, incomplete or contain inaccurate information.

    In this guide, I’ll show you how to use Library of Leaks, perform searches, interpret results responsibly and illustrate common use cases.

    Ready to get started? Let’s go ⬇️

    Unlike many breach intelligence tools, Library of Leaks requires zero installation as it’s an easy-to-access web tool. It also requires little to no technical ability (you just need to have an idea of what you’re looking for) as it’s essentially the same as scrolling an archive site.

    All you need to do is visit https://search.libraryofleaks.org/ and you’re all set to start querying — no login needed.

    Library of Leaks accepts a wide range of search terms depending on what you’re investigating. Whether you’re researching an individual, organisation or online alias, each search can provide new pivot points for further investigation.

    Searching an email address is often the quickest way to determine whether it has appeared within publicly indexed breach datasets.

    Example: person@example.com

    Depending on the dataset, results may include associated usernames, names, passwords (where historically exposed), breach names and other metadata.

    🗒️ Treat any findings as investigative leads and corroborate them with additional sources before drawing conclusions.

    Many usernames appear across multiple breaches.

    Example: John Doe

    This can help reveal additional accounts, aliases or historical activity associated with that identity, helping you expand your investigation beyond a single data source.

    Searching a company domain can help identify accounts associated with an organisation.

    Example: example.com

    This is particularly useful during external exposure assessments, security reviews, corporate investigations, and incident response.

    🗒️ Remember, historical breach data may include former employees or accounts that are no longer active.

    Where available within indexed datasets, phone numbers can also be searched.

    Example: 1234567890

    This provides another useful pivot point when investigating digital identities.

    Library of Leaks also supports searching general keywords and business names.

    Examples: OSINT

    Google Inc

    Keyword searching can reveal references across multiple datasets that may provide useful investigative leads, but also likely needs filtering down as you can wind up with tens of thousands of results.

    Aha, so you’ve got 10,000+ results and you need to filter them out so you can actually find some useful nuggets of information? Head to the sidebar and narrow it down.

    You can filter by date, entity type, country, language, emails and phone numbers to name a few:

    Search results typically display information extracted directly from historical datasets. This can be in the form of webpages, emails, plain text files, PDF docs and more. Information within files could include email addresses, usernames, password hashes, names, phone numbers, physical addresses, database names, dates and a whole ton of both relevant and wholly irrelevant data.

    Not every result will contain every type of dataset, and the quality and completeness of data will differ between breaches.

    Library of Leaks naturally fits into a number of OSINT workflows.

    Library of Leaks is particularly useful for determining whether an identifier has appeared in historical breach datasets. Results may reveal compromised credentials, password hashes, historical plaintext passwords (where available), associated usernames and breach names. This can help assess credential exposure, identify password reuse risks and support security investigations.

    By correlating email addresses, usernames, names, and phone numbers across multiple datasets, Library of Leaks helps build a broader picture of an individual’s digital footprint. Each identifier can become a new pivot point, uncovering additional accounts, aliases or historical information that may support an investigation.

    Searching a company’s domain can identify employee accounts that have appeared in historical breaches, providing insight into an organisation’s exposure. This supports external security reviews, attack surface assessments, incident response and security awareness activities.

    🗒️ Remember that older datasets may include former employees or inactive accounts.

    Historical breach data can provide valuable context when investigating threat actors or suspicious online activity. Searching aliases, usernames or email addresses may uncover additional identifiers, historical accounts or relationships that generate new investigative leads and enrich wider intelligence collection efforts.

    One of Library of Leaks’ greatest strengths is its ability to generate new investigative leads.

    For example:

    Email address → Username

    Username → Additional breach

    Breach → Phone number

    Phone number → Name

    Name → Additional accounts

    Following these pivots is often where the greatest investigative value lies.

    Library of Leaks indexes publicly searchable breach information but it does not provide authority to misuse that information.

    Always:

    • Verify findings against original source documents wherever possible before publishing or relying on them.

    • Recognise that leaked or public datasets may be incomplete, outdated, altered or lack important context.

    • Avoid treating the inclusion of an individual or organisation in a dataset as evidence of wrongdoing or unlawful activity.

    • Respect applicable laws, copyright, licensing terms and ethical standards when accessing, reproducing or sharing leaked materials.

    • Consider privacy, legal and reputational implications when reporting on individuals or organisations identified in public or leaked records.

    Here are a few ways to get more from Library of Leaks:

    • Treat every result as a new pivot point. Search newly discovered usernames, email addresses, phone numbers and domains to expand your investigation.

    • Start with the most unique identifier available, such as an email address or phone number, before broadening your searches to names or keywords.

    • Search both full domains and individual email addresses when investigating organisations, as each can reveal different information.

    • Record which breach datasets your findings originated from to make verification and reporting easier later in the investigation.

    • Corroborate findings using archived websites, company registries, social media and other OSINT sources before drawing conclusions.

    • Compare results with platforms such as Have I Been Pwned, DeHashed or Intelligence X to identify additional exposures or validate historical findings.

    • Remember that historical breach data can be incomplete, outdated or inaccurate, so absence from Library of Leaks does not necessarily mean an identifier has never been exposed.

    🏁 New CTF Challenge Live – RANSOMWARE GROUP

    A new CTF challenge has been posted on our CTF website. This week’s challenge involves investigating a .onion URL linked to a ransomware group and using DARKINT to identify the group behind the leak and the AI company they targeted.

    Start competing in our Capture the Flag (CTF)

    🪃 If you missed the last CTF, here’s a link to catch up.

    Last week’s CTF challenge featured a challenge titled “THE BREACH” where participants were tasked with finding the first and most recent time a threat actor’s email address appeared in public data breaches using a tool featured in one of our previous newsletter.

    Challenge solution WU :

    To solve this challenge, participants had to use the tool “MailAccess”, presented in the newsletter. Querying the email, they could find the asked dates.

    💡 Remember OSINT != tools. Tools help you collect data, but the output of a tool is not intelligence. You must analyse, verify, receive feedback, refine your findings and produce a final, actionable product before it becomes intelligence.

    ✅ That’s all for this issue of The OSINT Newsletter. Thanks for reading and supporting this publication with a paid subscription.

    By upgrading to paid, you’ll get access to the following:

    👀 All paid posts in the archive. Go back and see what you’ve missed!

    🚀 If you don’t have a paid subscription already, don’t worry. There’s a 7-day free trial. If you like what you’re reading, upgrade your subscription. If you can’t, I totally understand. Be on the lookout for promotions throughout the year.

    🚨 The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMozilla updates GPG signing key for Firefox releases after exposure
    Next Article No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests
    admin
    • Website

    Related Posts

    News

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026
    News

    Mozilla updates GPG signing key for Firefox releases after exposure

    August 11, 2026
    News

    Infosec News Nuggets — August 11, 2026 – AboutDFIR

    August 11, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202639 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202639 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026

    The OSINT Newsletter – Issue #118

    August 11, 2026

    Mozilla updates GPG signing key for Firefox releases after exposure

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.