Types of data breaches that show up in a checker are usually a stealer log, a combo or stuffing list, a scrape, or an email-only spam list. Read the data types on the match, then use the password, phone, or identity playbook. EmailLeaked does not claim exclusive dark-web files. Last updated: September 2026.
Types of data breaches that land in a consumer checker are not all “a company was hacked last Tuesday.” A match might be malware logs from someone else’s PC, a stuffing kit stitched from older leaks, a scrape of phones and profile fields, or an email-only spam list. The incident name is a label. The data types on the row pick the next step.
This page is the plain-English map. For how a lookup actually works — collected records, not a live crawl — use how email breach checkers work. For the hour-by-hour list after any match, use what to do after a data breach. Cryptic compiler names such as Synthient are decoded in What is Synthient? Breach names explained.
What are the main types of data breaches in plain English?
Hold four everyday types. A fifth shows up when government IDs are listed.
| Type | What was copied | First job |
|---|---|---|
| Stealer log | Saved passwords, often the site, sometimes browser cookies | Change passwords, sign out everywhere, scan for malware |
| Combo / stuffing list | Email-and-password pairs from many older leaks | Kill reuse. There is no company login to reset |
| Scrape | Phones, names, emails, profile fields — usually no passwords | Phone and phishing playbook |
| Spam / email-only list | Confirmed-active addresses, sometimes names | Expect phishing. Still unique inbox password + 2FA |
| Identity / people-search dump | Names, addresses, dates of birth, government IDs | Freeze credit. A password change is not enough |
A site breach is one organisation’s user table. Many of the largest checker rows are not that. They are compilations, scrapes, or threat-intel files with a brand you never signed up for.
As of 2026, public catalogs still describe on the order of a thousand named incidents and more than 12 billion compromised records. The Verizon 2024 Data Breach Investigations Report again found stolen or guessed logins in a large share of web-application breaches. Old combo lists stay useful. New stealer logs keep arriving. Neither fact means a checker crawled hidden markets live.
We check industry-standard breach data sources. We do not claim exclusive dumps or a private underground feed. The breach catalog is where named incidents get a longer explainer.
- Read the data types before you invent a password leak.
- A compilation name is not a login page.
- A clean result is a snapshot for today, not a lifetime all-clear.
What does a stealer-log match mean?
A stealer log is the output of malware — an info-stealer — that infected a device and copied what the browser had saved: passwords, sometimes cookies, sometimes autofill.
If your address appears in a stealer-log row, it usually means one of two things: a device you own was infected, or you typed a login on a shared or work PC that was. It does not automatically mean someone is sitting in your inbox tonight. That difference is data breach vs email hacked.
The 2025 Synthient Stealer Log Threat Data row is this class: on the order of 183 million unique emails plus passwords, added as a threat-intel aggregation, not as a hack of a company called Synthient. Public analysis of that file found most addresses already in earlier catalogs, with a smaller set of new ones. Raw logs often also name the site. The email checker still shows a named match, not a live map of every URL in the log.
Treat a stealer-log match as the password playbook plus device hygiene:
- Change the password on email first, then everywhere you reused it
- Sign out of other sessions on important accounts
- Run a malware scan on the machines you actually use
- Turn on two-factor authentication so a stolen password is not enough
It is not an antivirus scan of the laptop in your bag performed by the checker. Paid “we saw malware on YOUR PC” pages are often a demo wall. We will not write that we searched every hidden market for your cookies.
What does a combo-list or stuffing-list match mean?
A combo list (combolist) is a file of email-and-password pairs stitched together from many older dumps, then de-duplicated so a bot can try them efficiently. That attack is credential stuffing. It does not guess. It replays reuse.
Collection #1 is the usual example: a January 2019 compilation of about 773 million unique email addresses and about 21 million unique passwords from more than 2,000 earlier incidents. There is no Collection #1 account. You cannot call support. The original shop may never be named.
Synthient Credential Stuffing Threat Data is the same class in a 2025 wrapper: on the order of 1.96 billion unique emails and 1.3 billion unique passwords gathered as threat intelligence, not a Gmail disclosure, and not the stealer-log slug. Headlines that treat a compilation as “your inbox was just hacked” collapse two stories.
A combo-list match means: a pair linked to you was in a stuffing kit. If you still use that password, or a close cousin, other sites are the risk. Unique passwords confine the damage. Password manager after a data breach is the change-list order. The printable order is the password reuse change checklist.
See which named incidents include your address. Check your email in known breaches → — free, no signup. We do not keep the address you type. Then read the data types before you pick a playbook.
What does a scrape match mean?
A scrape copies data that was already showing, or that a weak lookup tool would return: phone numbers, names, emails, workplace, relationship status. It is not a copy of stored passwords.
The 2019 Facebook scrape published for free in April 2021 is the usual example. Contemporary reporting put the set at about 533 million user records, almost all with a mobile number plus a Facebook ID, name, and gender. This lookup lists about 509 million unique emails because not every row had an inbox. Passwords were not in the file. Changing a Facebook password does not unsay a published number.
A scrape match is the phone and phishing playbook:
- Watch for SMS that already knows your name
- Ask your carrier about a port freeze or extra PIN
- Move important accounts off text-message codes onto an authenticator app or a passkey
- Treat unexpected “verify your Facebook” mail as hostile and open the real site yourself
Cambridge Analytica was a different Facebook story. An internal plaintext-password finding was a different Facebook story. Do not fold them into this match. Is Facebook safe after the data breach? is the product question. This page is the type.
What does a spam-list or email-only match mean?
Some compiled files are just addresses — a spam list or marketing dump. No password. Sometimes a name. The realistic harm is more phishing that uses a real old service name, not a stuffing bot walking into the bank.
Email-only is still not nothing. A confirmed-active inbox is worth money to people who send “your account will close” mail. Do not tap those links. Still give that inbox a unique password and a second factor, because the next file that includes you might add a password from somewhere else.
You cannot pay someone to remove the address from copies that already spread. There is no recall button. Anyone selling “dark web removal” after a free scan is describing a job that cannot finish.
If the row also lists a home address or date of birth but no password, you are closer to the identity playbook than the spam playbook. Read the fields. Do not guess.
Which next-step playbook should you use after each type?
Use the after-breach page. Jump to the section that matches the fields.
Password, combo list, or stealer log. Change the password on the named service if there is one, then everywhere you reused it. Run the password leak checker. Turn on 2FA or a passkey, starting with email. For a stealer log, also sign out everywhere and scan the device.
Scrape or exposed phone. Carrier PIN. Authenticator app over SMS. The phone section of the after-breach playbook. A password change is hygiene, not a cure for a published number.
Government ID, Social Security number, or people-search identity data. A password change does not expire an SSN. The 2024 National Public Data row is this class: later dumps list about 134 million unique emails plus names, phones, addresses, dates of birth, and government-issued IDs. Passwords were not included. The row is unverified. An email match is not proof your SSN sat in the first SSN-heavy file. Still use credit freeze after an SSN breach when identity fields were listed.
Email only. Phishing watch. Unique inbox password anyway. Recheck after the next company notice.
Confused by the name? Open the explainer under breaches. Then come back to this table. The name is the filing label. The fields are the job. The identifier you typed is a separate question — email vs phone vs username. Email vs phone vs username breach checks is that map.
Can a checker tell you which type you are in?
It can show a named incident and the data types that catalog recorded. That is usually enough to pick a playbook.
It cannot tell you:
- That we searched the entire dark web. We did not. Honest free consumer tools do not.
- That a private sale never reached a public index. Industry-standard sources are large. They are not complete.
- That your laptop is clean, even when a vendor mentions stealer logs.
- That you are safe forever. New incidents land throughout the year.
If two honest tools disagree, believe the match. Catalogs refresh on different schedules. Some hide sensitive incidents until you verify the inbox. A miss on one site is not a lifetime all-clear.
EmailLeaked does not claim a bigger archive or exclusive files for stealers, combos, or scrapes. Have I Been Pwned remains the gold-standard public index for named incidents. We are a complementary no-signup check with the result in this tab and a short next-step list. The product map is free data breach checkers.
- Stealer log — malware copied saved logins. Passwords plus device hygiene.
- Combo list — many older leaks, one stuffing file. Kill reuse.
- Scrape — phones and profile fields. Phone playbook, not a password vault.
- Spam / email-only — phishing risk. Still unique inbox password + 2FA.
- Identity dump — freeze credit. A password change is not enough.
- No exclusive dark-web claim. A match is a to-do list. A clean page is a snapshot.
Want the named incidents for the address you actually use? Check if your email was exposed →