2026.10.08

OpenExposure: From Leak to Lockdown

Breach checkers tell you that your data leaked. I wanted something that tells you what to do next.

Try it: openexposure.app

The problem with a list of company names

Type your email into most breach checkers and you get a list: Canva, Dropbox, a data broker you have never heard of. Then the page ends. You are left to work out which of those matter, what an attacker could actually do with them, and where to even start.

That gap is real enough that Google retired its own Dark Web Report in early 2026, saying it did not give people helpful next steps. The services that do give advice are mostly paid subscriptions, and the powerful lookup tools are built for investigating other people, not protecting yourself.

I wanted something free, focused on you, and practical enough to finish in one sitting.

What it does

Start with whatever you use. An email, a phone number or a username. For phone numbers it recognises the country and area code as you type, and numbers without a country code are read as US or Canada.

OpenExposure search box detecting a Canadian phone number with area code 416, Ontario
Figure 1Country and area code are detected live while typing.

See what leaked, all in one place. Breaches are checked across several sources and merged, so the same incident never shows up twice. You see which kinds of data leaked, not just where.

Results summary showing 8 breaches, 12 kinds of leaked data, 6 attack paths and 20 steps to fix
Figure 2The summary: breaches, the kinds of data exposed, and how much work the fix will take.

Understand how it could be used against you. Leaked data is most dangerous in combination. A phone number plus a name and birth date is enough to attempt a SIM swap. An email plus an old password is enough for automated login attempts across banks and shopping sites. OpenExposure turns your actual leaks into a short list of concrete attacks and explains each one in plain language. It also flags infostealer logs, which mean a device was infected and every saved password is at risk, not just one site's.

Attack path cards: password reuse, SIM swap, account recovery hijack, new accounts opened in your name, phishing, being found
Figure 3Attack paths built from the combination of what leaked.

See the whole picture. The footprint map connects everything found to what you searched. Pick an attack and it lights up exactly the pieces that attack relies on. As you work through the fixes, those pieces fade out.

Footprint map with the SIM swap attack highlighted, connecting phone numbers, addresses, birth dates and names to the searched email
Figure 4The footprint map with the SIM swap path highlighted.

Get a plan, not a list. Every attack maps to steps you can actually take, ordered by impact, with time estimates and direct links: the breached site's own change-password page, whether it offers two-factor sign-in and how to turn it on, your carrier's number lock, free credit freezes, and people-search opt-outs. Progress is saved in your browser, so you can come back to it.

Lockdown plan checklist with progress bar, time estimates and direct links to carriers and password managers
Figure 5The lockdown plan, grouped by what each step protects.

Privacy choices

  • What you search is never stored. Not in a database, not in logs. Reports are built on the fly and thrown away.
  • Passwords never leave your browser. The password check uses k-anonymity: only a short fragment of a hash is sent.
  • Anonymous counts only. Totals like searches per day and which breaches come up most, never who searched or what.
  • Built against misuse. If the same email or phone is looked up by many different people in a day, further lookups pause. This uses one-way fingerprints, not the value itself.
  • No sign-up, no ads, no tracking cookies.

What comes next

  • Verified mode. Confirm you own an email with a one-time code, which makes it safe to run deeper checks, such as finding old accounts registered to it.
  • Opt-in alerts when a verified address shows up in a new breach, with the fix steps included.
  • French, and more regions. Canadian French first, then carrier, credit bureau and opt-out steps beyond the US and Canada.
  • Account clean-up. Guided deletion for old accounts you no longer use, since the safest account is one that no longer exists.
  • Passkey guidance per site as more services support them.
  • Open trends. Publishing the anonymous numbers: which breaches people run into most, and which fixes they actually finish.

Try it

It takes about twenty seconds and there is nothing to sign up for.

Check your exposure at openexposure.app
Screenshots use a fictional person and an example.com address. Breach names are public incidents shown for illustration.