Changelog
BREACH HOUSE ALERTS
Want an alert every time a new post is published?
Choose the feeds and the countries you care about — we email you when they move.
Recent Updates
V1.6 September 2026
- Leak status you can filter by, everywhere: every listing — home, ransomware, groups and countries — now carries a Leak status column and a filter for leaked, pending or deleted. Records we have not checked yet show a dash rather than a guess.
- Leak coverage at a glance: the home page and every country page get a coverage chart — the ransomware breakdown (leaked / pending / deleted) drawn as a ring, with the totals for data breaches, stealer logs and leads beside it.
- The operator's download link (Enterprise): for a ransomware leak that is actually published, Enterprise accounts now see the operator's own Tor download link on the victim page and in the API; everyone else sees that a download exists and what plan reaches it.
- Akira, fully tracked: Akira publishes on a terminal-style site instead of a normal index. We now drive that terminal to read each victim's status and its download link, the same as any other group.
- Cleaner charts and wider tables: the attack timelines were redrawn to stay readable in both light and dark themes, and the records table no longer runs off the side of the page.
Previous Updates
V1.5 September 2026
- Leak site screenshots: victim pages now show what the operator actually published, captured from the leak site itself. On group sites that list every victim on one page, the capture is cropped to that victim's own entry, so you see their listing and nothing else.
- Leak status, next to the publication date: each record now says whether the files have actually been published or the listing is still a countdown, together with the date we last checked. The verdict is read from the operator's own page, not inferred from the date.
- Proof files, sorted by what they are: the documents an operator posts as proof are now labelled — passport, tax form, medical record, invoice, payroll — with the readable text shown underneath each one, so you can tell a logo apart from a scanned ID without opening anything.
- What's In This Leak: a new panel describing the composition of a leak — record counts and the classes of data involved — sitting alongside Dark Web Exposure in the same row.
- Capture history: Enterprise accounts get the full timeline of every capture taken of a listing, which is what shows a leak growing, being edited or disappearing. Everyone else sees the history exists, blurred.
- Right victim, right evidence: where a group publishes all its victims on a single index page, proof files were being attached to whichever record shared the page. Every image is now tied to the entry it was actually published under, and the mis-attributed ones have been detached.
- Listings that lead somewhere: repaired the source links on records that pointed at a group's bare homepage or at a host that no longer resolves, so "view original listing" reaches the listing.
- Tor Gateway from your account: Enterprise accounts now have a Tor Gateway panel in Account, so opening a leak site no longer means finding the feature first. Everyone else can see what it does and what plan it needs.
- One list, one unsubscribe: the newsletter box in the footer and the alerts modal now write to the same subscriber store, and the unsubscribe link works for both. Product updates and data alerts stay separate: subscribing to one does not sign you up for the other.
- Pricing: "Support Us" is now Pricing, and it takes you straight to the plans.
- Clearer legal notice: the disclaimer on record pages has been rewritten to state plainly what we do and do not do: we record what operators publish in the open, we do not buy data, we do not access any private system, and we alter nothing.
Previous Updates
V1.4 August 2026
- Typical Attacks, in plain English: every ransomware group now explains how it actually breaks in — mapped to MITRE ATT&CK where the framework covers the group, and assessed from observed behaviour where it doesn't. It replaces the old raw "Tools Used" dump.
- Tools, wallets and ransom notes: group profiles now carry the tooling seen in their intrusions, their tracked cryptocurrency wallets with amounts received, and the text of their real ransom notes.
- Email alerts: subscribe to a country, a sector or a whole feed and get a digest when new entries land. One-click unsubscribe in every message.
- Country pages rebuilt: about 16x faster to load, with server-side pagination and a new sector filter. Category pages gained the mirror-image country filter.
- Countries are links everywhere: every country in every table now takes you to that country's page.
- Tor gateway (Enterprise): open an onion site directly from Breach House, no Tor Browser required — available in the web app and in the API.
- Country and sector reports in the API: generate a full period report for any country or sector.
- Mirror uptime: group pages now show whether each leak site is reachable, when it was last checked, and a 7-day availability history.
- Sector taxonomy cleaned up: duplicate categories that split the same sector into two counts have been merged, with redirects from the retired names.
- Feedback button: report anything that looks wrong from any page, screenshots included.
Earlier Updates
V1.3 June 2026
- Richer Detail Pages: Breach, infostealer and ransomware-victim pages now build a unique, readable summary from the available data (sector, location, timeline and threat actor) instead of an empty placeholder.
- Distinct Page Layouts: Each record type now has its own context, headings and wording, so breaches, infostealer logs and ransomware victims read differently.
- Smarter Search Indexing: High-value pages are surfaced to search engines while thin, data-poor entries are excluded, and the sitemap now lists only meaningful, valid URLs (split into indexed batches).
- API Authentication Fixed: API tokens are now validated correctly, resolving the spurious "invalid token" errors.
- API Daily Quotas: Each token's daily request limit is now enforced, with live usage shown in your account.
Older Updates
V1.2 March 2026
- New Design: Completely revamped interface with modern cyberpunk aesthetics.
- New Victim Pages: Detailed intelligence and timeline for each affected organization.
- Early Identification: Enhancements for early victim detection and rapid categorization.
- Activity Categorization: Added breakdown charts for attacks by industry sector and business category.
- Enhanced Group Pages: Much more detailed actor information, including IoCs, TTPs, interactive charts, and communications.