Here it is: https://t.co/vXTITy35Gw
Searches over 40 billion breach records.
Personally tested & saw a lot of my compromised passwords.
Check if any of your data is out there for free
SIM-swap attempts. "Your bank" calling. Endless smishing.
All three start with a number someone bought. Take it off the lists and the attack surface shrinks.
#SIMSwap#Smishing#Privacy#DataBrokers
Built this because I got tired of data brokers selling my information
Searches over 40 billion breach records - you don't need an account to run it.
Here it is: https://t.co/B4H8BY1NoL
Check if any of your data is out there for free
One-time removal isn't removal. Brokers repopulate from upstream sources, so a cleared listing reappears weeks later.
Every bump gets caught by a weekly re-scan and refiled — until it stays gone.
#DataBrokers#Privacy#DataRemoval
Built this because I got tired of data brokers selling my information
Searches over 40 billion breach records - you don't need an account to run it.
Here it is: https://t.co/B4H8BY1NoL
Check if any of your data is out there for free
@DouglasBarclay3 No - you simply enter your email to see what breaches your email has been a part of (if any) and if it has, it will show you what information was breached - so if you see that your password was part of a breach, you know to change it - informative tool
Here it is: https://t.co/vXTITy35Gw
Searches over 40 billion breach records.
Personally tested & saw a lot of my compromised passwords.
Check if any of your data is out there for free
SIM-swap attempts. "Your bank" calling. Endless smishing.
All three start with a number someone bought. Take it off the lists and the attack surface shrinks.
#SIMSwap#Smishing#Privacy#DataBrokers
Here it is: https://t.co/vXTITy35Gw
Searches over 40 billion breach records.
Personally tested & saw a lot of my compromised passwords.
Check if any of your data is out there for free
Deleting the app doesn't delete the account.
The profile stays live, the data stays held, and the breach notification goes to an inbox you stopped checking.
Delete the account. Then the app.
Your work email in a breach is a company problem, not a personal one.
It gives attackers your employer, your role, your naming convention, and a foothold for targeting colleagues.
Don't use it for personal signups.
Nobody gets breached and finds out immediately.
Median dwell time is measured in months. By the time a company discloses, the data has been sold, resold, and merged into profiles.
Speed of disclosure is not speed of theft.
Free antivirus that scans your browsing, sells telemetry, and injects "offers" is not free.
Your OS already ships with something decent. Most third-party security suites are the thing they claim to protect you from.
QR codes are just links you can't read.
Every instinct you've built about checking a URL before clicking is disabled by design.
Phishing moved to physical stickers over real menus and parking meters. It works.
Encryption at rest sounds great until you ask who holds the key.
If the company can read your data, so can anyone who compromises the company. End-to-end means they can't. The difference is everything.
The weakest link in your security isn't your password.
It's the support agent at a company you signed up to in 2016, who can reset your account for anyone who sounds convincing enough.
"We take your privacy seriously" appears in almost every breach notification ever written.
If a company only tells you what it holds after losing it, that's the answer to how seriously.
Attackers know your renewal dates.
Insurance, domain, hosting, TV licence - all findable. A phishing email that arrives the same week something genuinely expires is far harder to spot.
Timing is a targeting technique.
Ransomware crews don't break in anymore. They log in.
Stolen credentials from a previous breach, bought cheap, tried everywhere. No exploit, no zero-day, no genius.
Reused passwords are the attack.