Header illustration for "Your email is probably in a breach database. Here's how to audit your own exposure, lawfully"

"Your email is probably in a breach database. Here's how to audit your own exposure, lawfully"

Your email is probably in a breach database. Here's how to audit your own exposure, lawfully

Two items crossed the Hackers Arise OSINT feed recently: one on finding leaked secrets with TruffleHog, an open-source scanner that digs through Git repositories and their full commit history for accidentally committed API keys, tokens and passwords; another on investigating Google accounts with Ghunt, a tool that pulls publicly exposed Google profile data — Gaia ID, profile photos, Maps activity, active services — from just an email address. Both are written for attackers and investigators. Read them the other way and they describe something most Australians have never done: a proper audit of their own leaked digital footprint.

The breach data says you're in there

The odds aren't subtle. Troy Hunt — an Australian Microsoft regional director — runs Have I Been Pwned, the breach-search service the FBI itself pointed victims at after the Genesis Market takedown. Hunt has found his own email in 29 separate breaches, and the service has indexed billions of addresses, including the 773-million-address Collection #1 dump he documented back in 2019. Australia's own regulator reported 1,205 notifiable data breaches in 2025 — the highest since the scheme began — with malicious attacks behind the majority of them. Health, finance, government, education: if you've ever been a patient, customer, or student, assume your address is in circulation.

What leaked email addresses actually enable is credential stuffing: taking password lists from one breach and replaying them everywhere else. The Australian Signals Directorate's personal security guidance explicitly tells Australians to check Have I Been Pwned, change any reused passwords, and turn on multi-factor authentication. That's the lawful, official starting point, and it costs nothing.

The TruffleHog lesson: secrets outlive deletion

The TruffleHog article's sharpest point applies well beyond developers: even if a secret is removed from the current version of a file, it still lives in Git's history. Delete a leaked API key from your repo tomorrow and it remains extractable from every past commit. If you run any kind of small-business website, app or repository, it's worth scanning your own repositories — including history — for exposed credentials. TruffleHog is open source, classifies hundreds of secret types, and can verify whether a found credential is still live. Scanning your own repos is entirely lawful; scanning other people's is not, and the Hackers Arise material describes attack techniques we won't reproduce here.

For everyone else, the translation is: check what you've published. Old GitHub repos, pastebin-style rants, photos of whiteboards with credentials, config.php backups on a web server — the leak pattern is always "convenience now, exposure later".

The Ghunt lesson: your Google footprint is visible

Ghunt doesn't break into accounts — it extracts publicly exposed data from Google's own services. Run against an email address, it can surface a Gaia ID, profile photo, last profile-edit timestamp, Google Maps reviews and photos, and which Google services the account has active. The defensive takeaway is a ten-minute job: open Google's Security Checkup and Privacy Checkup, review what your Maps and YouTube activity reveals publicly, and audit third-party app access. Most people will find public Maps reviews tied to their home suburb, or years-old app grants they forgot about. Those are exactly the breadcrumbs an OSINT pass collects.

A lawful self-audit, in order

  1. Check every email address you own at Have I Been Pwned, including old ones. Use its Pwned Passwords service to test whether passwords you still use have appeared in breaches.
  2. Change anything reused to a unique passphrase, and put a password manager behind the lot. Reuse is the mechanism that turns one breach into ten.
  3. Enable MFA everywhere important — email and banking first, per ASD's first-steps guide. For accounts that support them, a hardware FIDO2 security key (disclosure: our own store) resists phishing in a way SMS codes don't.
  4. Run Google's Security and Privacy Checkups on every Google account, and trim public Maps/YouTube history.
  5. If you publish code, scan your own repositories for leaked secrets, including git history, and rotate anything found.

One boundary line, because the tools cut both ways: running these checks against accounts and systems you own is lawful self-defence. Running Ghunt or secret-scanning against other people is a different matter entirely — in Australia, the Privacy Act and state stalking/surveillance offences can attach, and unauthorised access to accounts is straight-up criminal. Audit yourself; don't investigate your neighbours.

This post is general information, not legal or security advice.

Image: "Password hacking illustration" by Santeri Viinamäki, CC BY-SA 4.0 via Wikimedia Commons.

← All posts