The OSINT Newsletter - Issue #118
OSINT Tool Tuesday: Library of Leaks
đ Welcome to OSINT Tool Tuesday. This week weâre looking at Library of Leaks; a web-based search engine that indexes hundreds of publicly available breach and leak datasets so you can search masses of exposed records from a single, simple interface. No command line, no software installation, and no account setup required â you can simply search and go.
đ¨ This tool has been added to the OSINT Resources for Open Directories page on The OSINT Newsletter for easy reference later. That list serves as a roadmap for new tutorials in the future. If there are any tools youâd like to see added to the list and covered, please reach out to jake@osint.news with details.
đŞ If you missed the last newsletter, hereâs a link to catch up.
⥠Everything Must Go (Including Their OPSEC): OSINT on eCommerce and Marketplace
đď¸ If you prefer to listen, hereâs a link to the podcast instead.
Letâs get started. âŹď¸
Library of Leaks
Library of Leaks is a free online search platform that enables investigators to query hundreds of publicly indexed breach collections from a single website. Instead of hosting the leaks itself, it points you toward known sources across the OSINT ecosystem.
đŠ H/T: Distributed Denial of Secrets
The platform is particularly useful during the reconnaissance phase of an investigation when youâre trying to establish whether an individual, organisation or identifier has previously appeared within publicly available breach data.
Important Note: The presence of information within a breach dataset should never be interpreted as evidence of current compromise or wrongdoing. Many datasets are historical, duplicated, incomplete or contain inaccurate information.
In this guide, Iâll show you how to use Library of Leaks, perform searches, interpret results responsibly and illustrate common use cases.
Ready to get started? Letâs go âŹď¸
Getting Started
Unlike many breach intelligence tools, Library of Leaks requires zero installation as itâs an easy-to-access web tool. It also requires little to no technical ability (you just need to have an idea of what youâre looking for) as itâs essentially the same as scrolling an archive site.
All you need to do is visit https://search.libraryofleaks.org/ and youâre all set to start querying â no login needed.
Searching
Library of Leaks accepts a wide range of search terms depending on what youâre investigating. Whether youâre researching an individual, organisation or online alias, each search can provide new pivot points for further investigation.
Email Addresses
Searching an email address is often the quickest way to determine whether it has appeared within publicly indexed breach datasets.
Example: person@example.com
Depending on the dataset, results may include associated usernames, names, passwords (where historically exposed), breach names and other metadata.
đď¸ Treat any findings as investigative leads and corroborate them with additional sources before drawing conclusions.
Usernames
Many usernames appear across multiple breaches.
Example: John Doe
This can help reveal additional accounts, aliases or historical activity associated with that identity, helping you expand your investigation beyond a single data source.
Domains
Searching a company domain can help identify accounts associated with an organisation.
Example: example.com
This is particularly useful during external exposure assessments, security reviews, corporate investigations, and incident response.
đď¸ Remember, historical breach data may include former employees or accounts that are no longer active.
Phone Numbers
Where available within indexed datasets, phone numbers can also be searched.
Example: 1234567890
This provides another useful pivot point when investigating digital identities.
Keywords and Business Names
Library of Leaks also supports searching general keywords and business names.
Examples: OSINT
Google Inc
Keyword searching can reveal references across multiple datasets that may provide useful investigative leads, but also likely needs filtering down as you can wind up with tens of thousands of results.
Filtering Results
Aha, so youâve got 10,000+ results and you need to filter them out so you can actually find some useful nuggets of information? Head to the sidebar and narrow it down.
You can filter by date, entity type, country, language, emails and phone numbers to name a few:
Understanding Results
Search results typically display information extracted directly from historical datasets. This can be in the form of webpages, emails, plain text files, PDF docs and more. Information within files could include email addresses, usernames, password hashes, names, phone numbers, physical addresses, database names, dates and a whole ton of both relevant and wholly irrelevant data.
Not every result will contain every type of dataset, and the quality and completeness of data will differ between breaches.
Investigative Use Cases
Library of Leaks naturally fits into a number of OSINT workflows.
Credential Exposure Discovery
Library of Leaks is particularly useful for determining whether an identifier has appeared in historical breach datasets. Results may reveal compromised credentials, password hashes, historical plaintext passwords (where available), associated usernames and breach names. This can help assess credential exposure, identify password reuse risks and support security investigations.
Identity Research
By correlating email addresses, usernames, names, and phone numbers across multiple datasets, Library of Leaks helps build a broader picture of an individualâs digital footprint. Each identifier can become a new pivot point, uncovering additional accounts, aliases or historical information that may support an investigation.
Corporate Investigations
Searching a companyâs domain can identify employee accounts that have appeared in historical breaches, providing insight into an organisationâs exposure. This supports external security reviews, attack surface assessments, incident response and security awareness activities.
đď¸ Remember that older datasets may include former employees or inactive accounts.
Threat Intelligence
Historical breach data can provide valuable context when investigating threat actors or suspicious online activity. Searching aliases, usernames or email addresses may uncover additional identifiers, historical accounts or relationships that generate new investigative leads and enrich wider intelligence collection efforts.
Lead Generation
One of Library of Leaksâ greatest strengths is its ability to generate new investigative leads.
For example:
Email address â Username
Username â Additional breach
Breach â Phone number
Phone number â Name
Name â Additional accounts
Following these pivots is often where the greatest investigative value lies.
OPSEC Considerations
Library of Leaks indexes publicly searchable breach information but it does not provide authority to misuse that information.
Always:
Verify findings against original source documents wherever possible before publishing or relying on them.
Recognise that leaked or public datasets may be incomplete, outdated, altered or lack important context.
Avoid treating the inclusion of an individual or organisation in a dataset as evidence of wrongdoing or unlawful activity.
Respect applicable laws, copyright, licensing terms and ethical standards when accessing, reproducing or sharing leaked materials.
Consider privacy, legal and reputational implications when reporting on individuals or organisations identified in public or leaked records.
Additional Tips
Here are a few ways to get more from Library of Leaks:
Treat every result as a new pivot point. Search newly discovered usernames, email addresses, phone numbers and domains to expand your investigation.
Start with the most unique identifier available, such as an email address or phone number, before broadening your searches to names or keywords.
Search both full domains and individual email addresses when investigating organisations, as each can reveal different information.
Record which breach datasets your findings originated from to make verification and reporting easier later in the investigation.
Corroborate findings using archived websites, company registries, social media and other OSINT sources before drawing conclusions.
Compare results with platforms such as Have I Been Pwned, DeHashed or Intelligence X to identify additional exposures or validate historical findings.
Remember that historical breach data can be incomplete, outdated or inaccurate, so absence from Library of Leaks does not necessarily mean an identifier has never been exposed.
đ New CTF Challenge Live - RANSOMWARE GROUP
A new CTF challenge has been posted on our CTF website. This week's challenge involves investigating a .onion URL linked to a ransomware group and using DARKINT to identify the group behind the leak and the AI company they targeted.
Start competing in our Capture the Flag (CTF)
đŞ If you missed the last CTF, hereâs a link to catch up.
Last weekâs CTF challenge featured a challenge titled âTHE BREACHâ where participants were tasked with finding the first and most recent time a threat actor's email address appeared in public data breaches using a tool featured in one of our previous newsletter.
Challenge solution WU :
To solve this challenge, participants had to use the tool "MailAccess", presented in the newsletter. Querying the email, they could find the asked dates.
đĄ Remember OSINT != tools. Tools help you collect data, but the output of a tool is not intelligence. You must analyse, verify, receive feedback, refine your findings and produce a final, actionable product before it becomes intelligence.
â That's all for this issue of The OSINT Newsletter. Thanks for reading and supporting this publication with a paid subscription.
By upgrading to paid, youâll get access to the following:
đ All paid posts in the archive. Go back and see what youâve missed!
đ If you donât have a paid subscription already, donât worry. Thereâs a 7-day free trial. If you like what youâre reading, upgrade your subscription. If you canât, I totally understand. Be on the lookout for promotions throughout the year.
đ¨ The OSINT Newsletter offers a free premium subscription to all members of law enforcement. To upgrade your subscription, please reach out to LEA@osint.news from your official law enforcement email address.









