Skip to content

What is breach monitoring?

Separate problem from data brokers, and worth understanding as its own thing.

  • A broker publishes your information deliberately, as a product. You can ask them to stop, and this is most of what Bighound does.
  • A breach is data stolen from a company you trusted. It’s already copied, traded and archived. There is nothing to opt out of — the data is out, permanently.

That’s why breach findings in Bighound offer “Acknowledge” rather than “Remove me”. Pretending otherwise would be dishonest about what’s possible.

We check every email address on your record against a corpus of known breach data. We do not maintain our own breach database and we do not store breach contents — we check whether your address appears, and record the breach’s name and date.

To do that check, we send your email address to a third-party breach-index provider (XposedOrNot). There is no way to ask “has this address been breached?” without asking someone who holds the breach index, so the address does leave Bighound for that lookup. We send only the address, never your name or anything else, and we don’t store what the provider sends back beyond the breach’s name and date. We’d rather tell you this plainly than imply the check happens by magic on our own server.

  1. Change that password, and don’t reuse it anywhere.
  2. Turn on two-factor for that account, if it offers it.
  3. If the breach included security questions, change those too — they’re often reused across accounts and never rotate.
  4. Mark it acknowledged in Bighound so it stops competing for your attention.

A password manager makes 1 and 2 dramatically easier and is the single highest-value security change most people can make.