15-20 sources per investigation
Security

Data Breach

By Seme Research Team · Updated May 22, 2026

Definition

A Data Breach is an incident where protected or confidential data is accessed, disclosed, or stolen by unauthorized parties. Common breach types include hacking, insider threats, physical theft, and accidental exposure. Breached data — often found on dark web marketplaces, paste sites, and breach notification services like HaveIBeenPwned — can be a valuable source of investigative information, though its use raises significant ethical and legal considerations. In identity investigation, breach data may reveal aliases, email addresses, password patterns, account associations, and previously unknown online identities. The ethical use of breach data requires careful consideration of privacy laws, data protection regulations, and the distinction between publicly available breach indexes and raw leaked data.

How It Works

Breach data analysis in identity investigation follows strict ethical guidelines. Step 1 — Index Check: querying breach notification services (HaveIBeenPwned, DeHashed) to identify which breaches contain the subject's email addresses. Step 2 — Breach Assessment: evaluating the source, date, and type of each breach to assess data reliability and recency. Step 3 — Pattern Analysis: examining email-to-account mappings, username patterns, and password characteristics (without accessing actual passwords) to identify alias usage and account associations. Step 4 — Cross-Reference: linking discovered accounts to the subject's known digital footprint through entity resolution. Step 5 — Legal Review: ensuring all breach data analysis complies with applicable privacy laws and investigation regulations.

Example

Investigating a person's digital presence through breach data reveals: their primary email "john@company.com" appears in 3 breaches (LinkedIn 2012, Adobe 2013, Dropbox 2012). A secondary email "jdoe_personal@gmail.com" found in the LinkedIn breach appears in 5 additional breaches, revealing accounts on platforms the person doesn't publicly acknowledge. Username "jdoe82" from the Adobe breach matches their GitHub handle. These breach-derived connections help build a more complete digital footprint while respecting ethical boundaries by using only publicly available breach indexes.

Applications

  • Digital footprint expansion for identity investigation
  • Account discovery for legal discovery proceedings
  • Security assessment of organizational exposure
  • Fraud investigation through alias and account linking

Related Terms

Platform Data

15-20
Sources/Investigation
78%
Avg Trust Score
25+
Glossary Terms
10-30 min
Investigation Time

Related Resources