WhatBreach
OSINT tool to find breached emails, databases, pastes, and relevant information
Install / Use
/learn @Ekultek/WhatBreachREADME
WhatBreach
WhatBreach is an OSINT tool that simplifies the task of discovering what breaches an email address has been discovered in. WhatBreach provides a simple and effective way to search either multiple, or a single email address and discover all known breaches that this email has been seen in. From there WhatBreach is capable of downloading the database if it is publicly available, downloading the pastes the email was seen in, or searching the domain of the email for further investigation. To perform this task successfully WhatBreach takes advantage of the following websites and/or API's:
- WhatBreach takes advantage of haveibeenpwned.com's API. HIBP's API is no longer free and costs 3.50 USD per month. To get an API key please see here
- WhatBreach takes advantage of dehashed.com in order to discover if the database has been seen in a breach before. WhatBreach provides a link to a dehashed search for effective downloading
- WhatBreach takes advantage of hunter.io's API (requires free API token) this allows simple and effective domain searching and will provide further information on the domain being searched along with store the discovered results in a file for later processing
- WhatBreach takes advantage of pastes from pastebin.com that have been found from HIBP. It will also provide a link to the paste that the breach was seen in and is capable of downloading the raw paste if requested
- WhatBreach takes advantage of databases.today to download the databases off the website. This allows a simple and effective way of downloading databases without having to search manually
- WhatBreach takes advantage of weleakinfo.com's API (requires free API token) this provides an extra search for the email in order to discover even more public breaches
- WhatBreach takes advantage of emailrep.io's simple open API to search for possible profiles associated with an email, it also dumps all information discovered into a file for further processing
Some interesting features of WhatBreach include the following:
- Ability to detect if the email is a ten minute email or not and prompt to process it or not
- Check the email for deliverable status using hunter.io
- Ability to throttle the requests in order to help prevent HIBP from blocking you
- Download the databases (since they are large) into a directory of your choice
- Search either a single email or a text file containing one email per line
Examples
Help page:
usage: whatbreach.py [-h] [-e EMAIL] [-l PATH] [-nD] [-nP] [-sH] [-wL] [-dP]
[-vH] [-cT] [-d] [-s DIRECTORY-PATH] [--throttle TIME]
optional arguments:
-h, --help show this help message and exit
mandatory opts:
-e EMAIL, --email EMAIL
Pass a single email to scan for
-l PATH, -f PATH, --list PATH, --file PATH
Pass a file containing emails one per line to scan
search opts:
-nD, --no-dehashed Suppres dehashed output
-nP, --no-pastebin Suppress Pastebin output
-sH, --search-hunter Search hunter.io with a provided email address and
query for all information, this will process all
emails found as normal
-wL, --search-weleakinfo
Search weleakinfo.com as well as HIBP for results
misc opts:
-dP, --download-pastes
Download pastes associated with the email address
found (if any)
-vH, --verify-hunter Verify the emails found on hunter.io for deliverable
status
-cT, --check-ten-minute
Check if the provided email address is a ten minute
email or not
-d, --download Attempt to download the database if there is one
available
-s DIRECTORY-PATH, --save-dir DIRECTORY-PATH
Pass a directory to save the downloaded databases into
instead of the `HOME` path
--throttle TIME Throttle the HIBP requests to help prevent yourself
from being blocked
Simple email search:
python whatbreach.py -e user1337@gmail.com
_____
_ _ _ _ _ _____ _ |___ |
| | | | |_ ___| |_| __ |___ ___ ___ ___| |_ | _|
| | | | | .'| _| __ -| _| -_| .'| _| | |_|
|_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
Find emails and their associated leaked databases.. v0.1.5
[ i ] starting search on single email address: user1337@gmail.com
[ i ] searching breached accounts on HIBP related to: user1337@gmail.com
[ i ] searching for paste dumps on HIBP related to: user1337@gmail.com
[ i ] found a total of 9 database breach(es) pertaining to: user1337@gmail.com
---------------------------------------------------------------------------
Breach/Paste: | Database/Paste Link:
Dailymotion | https://www.dehashed.com/search?query=Dailymotion
500px | https://www.dehashed.com/search?query=500px
LinkedIn | https://www.dehashed.com/search?query=LinkedIn
MyFitnessPal | https://www.dehashed.com/search?query=MyFitnessPal
Bolt | https://www.dehashed.com/search?query=Bolt
Dropbox | https://www.dehashed.com/search?query=Dropbox
Lastfm | https://www.dehashed.com/search?query=Lastfm
Apollo | https://www.dehashed.com/search?query=Apollo
OnlinerSpambot | N/A
---------------------------------------------------------------------------
Searching with weleakinfo and haveibeenpwned:
python whatbreach.py -e user1337@gmail.com -wL
_____
_ _ _ _ _ _____ _ |___ |
| | | | |_ ___| |_| __ |___ ___ ___ ___| |_ | _|
| | | | | .'| _| __ -| _| -_| .'| _| | |_|
|_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
Find emails and their associated leaked databases.. v0.1.5
[ i ] starting search on single email address: user1337@gmail.com
[ i ] searching breached accounts on HIBP related to: user1337@gmail.com
[ i ] searching for paste dumps on HIBP related to: user1337@gmail.com
[ i ] searching weleakinfo.com for breaches related to: user1337@gmail.com
[ i ] discovered a total of 12 more breaches from weleakinfo.com
[ i ] found a total of 21 database breach(es) pertaining to: user1337@gmail.com
[ w ] large amount of database breaches, obtaining links from dehashed (this may take a minute)
-------------------------------------------------------------------------------
Breach/Paste: | Database/Paste Link:
Pesfan.com | https://www.dehashed.com/search?query=Pesfan.com
Dailymotion | https://www.dehashed.com/search?query=Dailymotion
Apollo | https://www.dehashed.com/search?query=Apollo
MyFitnessPal | https://www.dehashed.com/search?query=MyFitnessPal
500px | https://www.dehashed.com/search?query=500px
Collection 4 | https://www.dehashed.com/search?query=Collection 4
OnlinerSpambot | N/A
LinkedIn | https://www.dehashed.com/search?query=LinkedIn
Dropbox.com | https://www.dehashed.com/search?query=Dropbox.com
500px.com | https://www.dehashed.com/search?query=500px.com
Dailymotion.com | https://www.dehashed.com/search?query=Dailymotion.com
Last.fm March 2012 | https://www.dehashed.com/search?query=Last.fm March 2012
Dropbox | https://www.dehashed.com/search?query=Dropbox
Myfitnesspal.com | https://www.dehashed.com/search?query=Myfitnesspal.com
Collection 1 | https://www.dehashed.com/search?query=Collection 1
Collection 2 | https://www.dehashed.com/search?query=Collection 2
Bolt.cd | https://www.dehashed.com/search?query=Bolt.cd
Lastfm | https://www.dehashed.com/search?query=Lastfm
Bolt | https://www.dehashed.com/search?query=Bolt
Collection 3 | https://www.dehashed.com/search?query=Collection 3
LinkedIn.com | https://www.dehashed.com/search?query=LinkedIn.com
-------------------------------------------------------------------------------
Downloading public databases:
python whatbreach.py -e user1337@gmail.com -d
_____
_ _ _ _ _ _____ _ |___ |
| | | | |_ ___| |_| __ |___ ___ ___ ___| |_ | _|
| | | | | .'| _| __ -| _| -_| .'| _| | |_|
|_____|_|_|__,|_| |_____|_| |___|__,|___|_|_|[][][]|_|
Find emails and their associated leaked databases.. v0.1.5
[ i ] starting search on single email address: user1337@gmail.com
[ i ] searching breached accounts on HIBP related to: user1337@gmail.com
[ i ] searching for paste dumps on HIBP related to: user1337@gmail.com
[ i ] found a total of 9 database breach(es) pertaining to: user1337@gmail.com
---------------------------------------------------------------------------
Breach/Paste: | Database/Paste Link:
Dailymotion | https://www.dehashed.com/search?query=Dailymotion
500px | https://www.dehashed.com/search?query=500px
LinkedIn | https://www.dehashed.com/search?query=LinkedIn
MyFitnessPal | https://www.dehashed.com/search?query=MyFitnessPal
Bolt | https://www.dehashed.com/search?query=Bolt
Dropbox | https://www.dehashed.com/search?query=Dropbox
L
Related Skills
feishu-drive
329.0k|
things-mac
329.0kManage Things 3 via the `things` CLI on macOS (add/update projects+todos via URL scheme; read/search/list from the local Things database)
clawhub
329.0kUse the ClawHub CLI to search, install, update, and publish agent skills from clawhub.com
codebase-memory-mcp
809High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 64 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
