sentinel · breach aggregator

sentinel

breaches you can verify — and publish without breaking the law

an index of data breaches from public sources and third-party apis. a result for an address goes only to that address — never onto the screen of whoever typed it.

address check verification gate
send verification link

nothing is shown before confirmation — not even “no hits”. the address is not stored if the link goes unused for 15 minutes. the query is hashed in the browser (sha-1, 6-char prefix).

→ link sent · valid 15 min · single use
open link (demo) change address

in production this step is the only moment the address exists in a log — as a salted hash, dropped after 24 h.

session confirmed · redakcja@example.pl · expires in 23 h 51 min end session
9datasets indexeddemo · api-fed in production
887datasets in hibpas of may 2025
902Mrecords 2025–2026proton dbo, 2026
0records we holdmetadata only, no record bodies
observatory

what actually leaked in 2025–2026, from third-party data, with the uncertainty stated

victim sectors
retail25.3%
technology15%
media & entertainment10.7%
other49%
proton data breach observatory, 794 breaches in 2025 (as of 2025-10-30)
victim size
1–249 staff
70,5%
250–999 staff
13,5%
1000+ staff
15,9%
source
proton, 2025
sources disagreeproton reported 794 breaches and 300M+ records for 2025 (2025-10-30); its 2026 update says 512 breaches and 902M+ records “since the start of 2025”. the figures are inconsistent; we do not average them — both are shown, dated.
breach index
region
#entitypublished recordsclassesstatus
001 ALAB Laboratoriaransomware, leaked in three batches 2023-11-27 ~55k national idhealthaddress confirmed sekurak
002 PL combolist (CERT Polska)aggregation of infostealer logs 2023-05-29 ~6M rows passwordsloginurl confirmed gov.pl
003 Morele.netUODO fine over PLN 3M (2024 decision) 2018-10 ~2.2M people contactpasswords confirmed rp.pl
004 American Heart of Polandransomware; UODO fine PLN 1,440,549 2025-02 21k+ healthhr confirmed wolters kluwer
005 SoundCloudsso vishing campaign 2026-01-26 29M contact confirmed proton dbo
006 Figure Lendingransom refused, 2.5 gb published 2026-01-08 3M passwordsssnaddress confirmed proton dbo
007 Bouygues Telecom6.4M customers, iban included 2025-09-23 6.4M ibanaddress confirmed proton dbo
008 Hallmarkno statement from the entity 2026-04-12 2.8M contactdob unconfirmed proton dbo
009 Miljödata (SE)municipal systems supplier 2025-09-15 undetermined passwordsnational id confirmed proton dbo

the date is the dataset publication date in the monitored source, not the intrusion date. “unconfirmed” means no statement from the entity — we publish with that label, after contacting them first.

dashboard · journalist / researcherverified account · api access
monitored objects
redakcja@example.pladdress · confirmed 2026-07-12 4 hits
example.pldomain · dns txt verified 12 mailboxes
alab.com.pltopic watch · metadata only watching
+ add domain
events
14:02new dataset: Hallmark · unconfirmed · entity notified 7 days earlier
09:41example.pl — 1 new mailbox in an infostealer log
yest.verification link expired (1) · hash deleted
export csv api keys
legal model

six decisions that keep sentinel on the clear side of gdpr

sources