Dehashed Favicon

Dehashed

Dehashed is a breach data search engine that allows security professionals to search for compromised credentials, email addresses, usernames, and passwords across multiple data breaches.

Breach Intelligence Credential Monitoring Incident Response Threat Intelligence

Overview

Dehashed provides cybersecurity professionals with a search interface to query a database of breached credentials. The platform aggregates data from publicly known data breaches, allowing users to search by email, username, domain, IP address, password hash, or plaintext password. Dehashed helps organizations identify compromised accounts, monitor for credential leaks, conduct threat intelligence investigations, and perform incident response. The service includes breach source attribution, password strength analysis, and supports API integration for automated monitoring of corporate domains. Dehashed operates across four service lines. Search allows users to query billions of records including names, email addresses, usernames, IP addresses, physical addresses, phone numbers, vehicle identification numbers, and web domains. Monitor alerts users when personal data such as email addresses appears in new leaks, with a free subscription allowing ten monitor tasks. The API enables integration into custom applications. WHOIS, launched in April 2025, provides web domain registration search including historical data from the past ten years, with Reverse WHOIS allowing searches by owner name, email, phone, or physical address. The platform supports advanced search operators including wildcards, regex patterns, and combined field queries such as email and username together. Search results include plaintext passwords when available, enabling analysis of password reuse patterns and credential exposure. The API supports multiple search types including simple, exact, regex, and OR/AND combinations across fields including email, IP address, username, password, hashed password, name, domain, VIN, phone, and address. Dehashed uses a freemium model. Search is free with an account, but viewing results requires a paid subscription. WHOIS searches require purchasing credits. API access uses separate pay-as-you-go credits at approximately $0.02 per query. The platform publishes a detailed search guide covering field-specific queries, wildcard usage, and data origin filtering.

Primary Use Cases

✔ Searching for compromised corporate email addresses to identify accounts that need password resets and additional security measures.
✔ Investigating password reuse attacks by searching for plaintext passwords and password hashes to understand attack patterns and strengthen password policies.
✔ Monitoring third-party breach exposure by querying domain-level data to assess the security posture of vendors, partners, and supply chain entities.
✔ Conducting identity fraud investigations by correlating usernames, email addresses, IP addresses, and physical addresses across breach datasets.
✔ Performing open source intelligence research using password reuse patterns to discover aliases and additional accounts linked to a subject.
✔ Investigating domain registration history through WHOIS and Reverse WHOIS to identify website ownership and previous registrants.

Frequently Asked Questions

Dehashed is a breach intelligence platform that aggregates data from thousands of publicly disclosed data breaches. It allows users to search for compromised credentials using multiple query parameters including email addresses, usernames, domains, IP addresses, and password hashes. The platform indexes and normalizes breach data to provide a comprehensive search interface for cybersecurity professionals.

Dehashed operates on a subscription-based model with multiple tiers. It offers a free tier with limited query capabilities to allow users to test the service. Paid plans provide enhanced features including unlimited searches, API access, bulk domain monitoring, advanced filtering, and enterprise-level support. Pricing details are available on the Dehashed website and vary based on usage requirements and organizational needs.

Dehashed allows searching across a wide range of compromised data types including email addresses, usernames, plaintext passwords, password hashes (MD5, SHA1, SHA256), IP addresses, domain names, and breach source information. The platform also provides metadata such as breach dates, source platforms, and password strength analysis to give context to the compromised credentials.

While both services track breached data, Dehashed offers more comprehensive search capabilities including password hash searching, IP address queries, and domain-level monitoring. Dehashed also provides access to plaintext passwords where available, password strength analysis, and API integration for automated monitoring. Have I Been Pwned focuses primarily on email address notifications and public breach awareness, whereas Dehashed targets security professionals needing detailed investigation and response capabilities.

Yes, Dehashed offers a comprehensive REST API that enables automated monitoring and integration with existing security tools and workflows. The API supports queries for email addresses, domains, and passwords, allowing organizations to build custom monitoring solutions. API access is available on paid subscription plans and includes rate limiting, authentication via API keys, and supports both synchronous and batch query capabilities for large-scale monitoring operations.

Metadata

Official Website Visit Website
Category Info

Tools that aggregate, search, and analyze data from data breaches to identify compromised credentials, monitor exposure, and support incident response and threat intelligence operations.

Added On

August 18, 2026

Last Updated

August 18, 2026

Malware Analysis

ANY.RUN is a cloud-based interactive malware sandbox that provides real-time analysis with over 600,000 security professionals and 15,000 or...

Security Operations

Velociraptor is an open-source endpoint visibility and collection tool using VQL queries for advanced incident response and digital forensic...