Back to Blog
Threat Intelligence10 min readAug 25, 2026

6 HaveIBeenPwned Alternatives for Breach Lookup in 2026

HIBP's search is built around email addresses. Six alternatives compared — usernames, names, phone pivots, stealer logs, and full identity views.

R

Revealer Intelligence Team

Revealer.US

If you need a haveibeenpwned alternative, the strongest options in 2026 are Revealer, DeHashed, Intelligence X, Snusbase, LeakCheck, and Scattered Secrets. HIBP is still the reference tool for email-based breach notification. Its consumer search, though, is built around a single identifier, and it is not a pivot tool. The six below fill in what HIBP leaves out: usernames, names, phone numbers, addresses, infostealer data, and cross-source recursion.

Why look past HaveIBeenPwned at all

Troy Hunt's HaveIBeenPwned is the reference point for breach notification, and it earned that status. It is trustworthy, transparent about sourcing, free for personal email checks, and its domain monitoring is genuinely useful for defenders. If your question is "has this specific email address appeared in a known breach?", HIBP should still be your first stop.

HIBP also has design constraints that push practitioners elsewhere. Those constraints are intentional. They still get in the way of OSINT work.

  • Email-centric search. The consumer lookup is built around email addresses. You cannot pivot from a username like j_doe_88, a person's name, or a physical address.
  • Infostealer data is not the core of the product. HIBP has begun exposing stealer-log detection, but its heart is still curated breach notification. People who work infostealer cases day to day keep a dedicated tool for identifier-level stealer pivots. That is where the freshest indicators of compromise actually live.
  • No reverse lookups. You cannot ask "which accounts belong to this person?" You can only ask "what breaches hit this exact identifier?"
  • No entity-level view. Real investigations rarely involve one email. They involve a person who uses three emails, two usernames, and a phone number interchangeably.

Those limits serve HIBP's consumer-notification mission. For OSINT they are gaps. The six tools below fill them in different ways.

Quick comparison

Tool Search keys Stealer log data Free tier Best for
Revealer Email, username, phone, name, address Yes Yes Combined account + breach pivots
DeHashed Email, username, name, phone, IP, address Partial Limited free search Public-record + breach crossover
Intelligence X Email, domain, URL, IP/CIDR, phone Some leaks include it Free search caps Historical / archival leak research
Snusbase Email, username, name, IP, password hash Yes (advertised) No (paid) Fast raw dump searching
LeakCheck Email, username, phone Limited Limited free checks Quick single-identifier checks
Scattered Secrets Username/email/password pairs No (cracked-credential focus) No Cracked-password validation

Details and honest trade-offs below. Coverage, pricing, and free-tier limits change frequently; these characterizations reflect publicly documented capabilities as of writing, so check each vendor's site before relying on specifics.

1. Revealer — combined identity and breach search

Revealer treats breach data as one layer of an identity graph rather than a standalone database. A single query by email, username, phone number, name, or address runs against 800+ platforms, public records, and known breach datasets, then connects the results back to the subject.

The difference shows up the first time you need to pivot. In an email-only workflow, finding [email protected] in three breaches is the end of the line. In Revealer, that same hit can surface associated usernames, previously unseen email aliases, and phone numbers. You feed those into a username search or reverse phone lookup and keep going. The AI Deep Search mode does this recursion for you: agent-driven people intelligence that follows identifiers across sources so you are not running each pivot by hand.

Two pieces of the product actually change how I work threat intel:

  • Stealer logs. The stealer logs module covers infostealer-derived credential and session material (the data malware captures at the moment of infection). That is how you learn an account was actively harvested, not merely listed in an old dump. Remediation advice changes when you know that.
  • Breach monitoring. Continuous monitoring tracks identifiers over time instead of one-off checks. Closer to HIBP's notifications, extended to non-email keys.

There is a free tier to start, self-serve plans from $12.99/mo, custom Enterprise pricing, and card or crypto payment. An API is available via the docs if you want breach checks inside your own tooling. HIBP's API is what a lot of teams actually build around, so parity there is not a nice-to-have.

Trade-off: breadth over minimalism. If all you ever need is "email in breach, yes/no," HIBP's simplicity wins. Revealer earns its keep when the identifier chain matters.

2. DeHashed

DeHashed indexes a large corpus of breach data plus public-record elements. The reason people switch to it is the search keys: username, name, phone number, IP address, and several other fields, not just email. Its advanced query syntax supports field-specific operators (username:, name:, ip:), which makes it feel closer to a research database than a consumer checker.

I reach for DeHashed on work that straddles breach data and public records. Skip-tracing adjacent cases, fraud reviews, checking whether a persona's claimed details appear anywhere real. Results typically show the source database each record came from, which helps you judge freshness and reliability.

Trade-offs: the interface is utilitarian and result quality varies by source; some records are old. Headline coverage numbers change over time, so treat anything on their marketing pages as approximate. Free search exists but is limited; meaningful use requires a paid subscription. Check their site for current rates.

3. Intelligence X

Intelligence X is less a breach checker than a leak archive with search. It indexes paste sites, darknet content, document leaks, and breach dumps, and lets you search by email, domain, URL, IP address or CIDR range, and phone number. Its bucket system for exploring related data is the distinctive part. You can pull entire datasets matching a selector, not just individual hits.

This is the one I open when the artifact might not be structured breach data at all. A spreadsheet leaked from a company's FTP server. A paste dump. A forum scrape. If your target showed up in a nonstandard leak, Intelligence X is more likely than most tools here to have it.

Trade-offs: archival breadth cuts both ways, and you will sift stale and low-relevance results. The free tier imposes strict search limits, and serious use means a paid tier. IntelX's paid plans are a bigger commitment than most options on this list, so check current pricing on their site. It also surfaces sensitive document content, so handle output with care under whatever legal framework governs your engagement.

4. Snusbase

Snusbase is a straightforward proposition: a fast, paid search engine over a curated set of breach and combolist databases, searchable by email, username, name, IP, and password hash. Snusbase also advertises infostealer-derived data, which keeps it relevant for checking whether credentials were captured by malware families instead of sitting in old breaches.

Search speed is the selling point. Results come back near-instantly, and the hash-search capability lets you work from cracked password lists backwards to identities. There's an API for automation.

Trade-offs: no free tier, and the dataset skews toward dumps circulating in cracker communities. Strong on combolists and stealer captures, thinner on the formally verified breaches HIBP curates. Sourcing transparency is limited relative to HIBP or DeHashed, so corroborate high-stakes hits through a second source before acting on them.

5. LeakCheck

LeakCheck sits closest to HIBP in spirit. Enter an email, username, or phone number and you get back the list of databases it appears in. The difference is the non-email keys HIBP omits. A limited number of free checks make it handy for quick spot-checks without spinning up a subscription.

Use it for lightweight verification during triage. When a report mentions an alias or a burner number and you just need to know whether it touches known breach data, LeakCheck answers faster than opening a full investigation platform. Phone-number breach search works reasonably well here, which matters because SMS-based account recovery makes phone-to-breach correlation genuinely useful in fraud work.

Trade-offs: depth and freshness vary; it aggregates broadly, not deeply. Free-tier rate limits get restrictive quickly, and result detail behind the paywall changes over time. As always with aggregator sites, verify anything consequential against a second independent source.

6. Scattered Secrets

Scattered Secrets takes a different angle. It does not let you browse raw dumps. It collects breach data, cracks the password hashes, and validates plaintext credentials. You subscribe to monitor your own domains, and alerts tell you which accounts had both exposed and cracked passwords. That is a much stronger risk signal than mere inclusion in a dump.

This one is for defensive monitoring. If your question is "which of my organization's credentials are practically reusable right now?" (as opposed to "what does this person look like online?"), Scattered Secrets answers it more precisely than any general breach search. Hash-cracking status is the filter that separates noise from urgent remediation.

Trade-offs: it's a defender tool, not an investigator tool. No reverse pivots, no username exploration, no stealer-log context. No free tier as of writing. And because it validates plaintexts, treat its outputs as live secrets and handle them accordingly.

Choosing between them: match the tool to the identifier

Pick based on what you start with and what you need to walk away with.

  1. Start from an email, end goal is notification → HIBP remains excellent, and Revealer's email lookup adds breach context around that same address if you need more than a yes/no answer.
  2. Start from a username or phone number → you need non-email keys: Revealer's data breach lookup, DeHashed, or LeakCheck.
  3. Suspect active malware capture, not just an old breach → prioritize dedicated stealer-log search: Revealer's stealer logs module or Snusbase's advertised stealer coverage.
  4. Building a full picture of a person → an identity-first platform: Revealer's people search or background check style aggregation, with breach data as one corroborating layer.
  5. Defending your own org's credentials → HIBP domain monitoring plus a cracking-aware service like Scattered Secrets.

Most investigators I know run two layers: a fast single-key checker for triage and an identity-graph platform for pivoting. The checker answers the question in front of you. The graph tells you which question to ask next.

One workflow rule that saves people from over-reading a hit: a match proves an identifier appeared in a dataset. It says nothing about who currently controls the account, whether the password was changed, or whether the record is accurate. Corroborate before you act, and prefer sources that disclose their provenance.

Staying on the right side of the line

All six tools are lawful to use for legitimate purposes: securing your own accounts, investigating fraud with proper authority, threat intelligence, and authorized engagements. What's not lawful is using breach data for unauthorized access, harassment, stalking, or impersonation. Every jurisdiction treats those seriously, regardless of which tool surfaced the data.

One compliance note for US readers: platforms in this space, including Revealer, are not consumer reporting agencies, and their output must not be used for employment, tenant screening, insurance, or credit eligibility decisions under the FCRA.

Frequently asked questions

Is there a free alternative to HaveIBeenPwned?

HIBP itself is free for individual email checks, and several alternatives offer limited free tiers. LeakCheck allows a small number of free checks, DeHashed has limited free search, and Revealer has a free tier to start. Free tiers are fine for occasional spot-checks; recurring investigative work generally needs a paid plan.

Can I search breaches by username or phone number instead of email?

Yes. HIBP's consumer search is built around email, but tools including DeHashed, LeakCheck, Snusbase, and Revealer support username and/or phone-number search against breach data. Coverage differs by tool, so run important identifiers through more than one.

Which alternatives cover infostealer logs?

Revealer has a dedicated stealer-logs module, and Snusbase advertises infostealer-derived data. HIBP has begun exposing stealer-log detection, but for identifier-level pivots on stealer data, practitioners still tend to keep one of the dedicated tools. Coverage in this category changes fast, so verify current datasets before you commit.

Do any of these offer an API like HIBP's?

HIBP offers a well-documented REST API. Among the alternatives, Snusbase and Revealer expose APIs. Revealer's is documented at its docs page, so automated breach screening can be rebuilt around non-email identifiers too.

Are these breach lookup tools legal to use?

Searching breach databases is legal for legitimate purposes such as protecting your own accounts, authorized security testing, fraud investigation, and threat intelligence. Using the same data for unauthorized account access, harassment, or identity fraud is illegal everywhere. Employment, tenant, and credit screening uses are off-limits under FCRA rules.

Should I replace HaveIBeenPwned or add to it?

Add to it. HIBP remains the best-maintained, most transparent source for email-based breach notification, and none of the alternatives fully replicate its trust position. The realistic setup is HIBP for email checks plus one alternative chosen for the identifiers and data classes HIBP doesn't cover.

Get started

Ready to check your exposure?

Create a free account and search live sources and known breach datasets.

Create account