I've been running XposedOrNot for years now. The pitch has always been simple: type in an email, find out if it's turned up in a data breach. Free, no signup, open source. Millions of lookups later, it still does exactly that.
But I've had a nagging feeling for a while that we were only answering half the question.
When someone asks "has my email been exposed?", a breach is the obvious answer. Some company got hacked, their user table leaked, your record was in it. Fair enough. But there's a second way your data ends up for sale, one that has nothing to do with a company being careless, and it's been growing fast: stealer logs.
I finally built coverage for them. We're starting with one source, AlienStealer, and more are on the way. Here's what it is, why it nagged at me, and how to actually use it.
Breach vs. stealer log, in plain terms







