Breach intelligence
DeHashed OSINT integration
Credential and breach intelligence from the DeHashed dataset.
DeHashed searches breach records for emails, usernames, phones, domains, names, and IPs — returning credential rows with database provenance, leak dates, and related identity fields. Its public list, as of 22 September 2026, has 24,051 data wells and 24,507,853,884 pieces of data.
How the DeHashed integration works
What happens between pressing run and reading a result.
- 1Choose email, username, phone, domain, name, or IP and select DeHashed.
- 2SearchIn maps your input type onto the matching DeHashed search field and issues the query.
- 3Matching breach records return with database provenance, leak metadata, and identity fields.
- 4SearchIn groups records by database, masks password and hash fields behind a reveal toggle, and keeps totals from upstream.
Data sources
SearchIn queries DeHashed by email, username, phone, domain, name, or IP. The figures below are from DeHashed’s public data-wells page, so you can see the size of the corpus before you spend a query.
- Data wells
- 24,051
- Pieces of data
- 24.51 billion
- Stats checked
- 22 September 2026
DeHashed’s published total is 24,507,853,884 pieces of data across those wells. That is a record count, not a count of unique people.
Supported inputs & pricing
Prices are USD. LeakRadar includes 1,000 credential unlocks in the query price, then $0.50 per extra 1,000. OSINT Industries is $0.60 plus optional premium modules at $1.80. Other integrations are flat per query. Full SearchIn rates are on pricing.
| Input type | Price |
|---|---|
| Emailemail | $0.30 |
| Usernameusername | $0.30 |
| Phonephone | $0.30 |
| Domaindomain | $0.30 |
| Namename | $0.30 |
| IP addressip | $0.30 |
Why run DeHashed through OSINTverse
You can always buy DeHashed directly. Here is what changes when the same data comes through SearchIn instead. Full write-up: OSINTverse vs DeHashed.
| DeHashed directly | Through OSINTverse | |
|---|---|---|
| Getting started | DeHashed sells its own paid subscription with an API key bound to a single account. | Sign in, top up from $10, and run DeHashed the same minute — no vendor contract, seat, or sales call. |
| What a query costs | Plan, credit pack, or contract pricing set by the vendor and paid up front. | Pay per query from your prepaid balance — DeHashed starts at $0.30 for email lookups, with the exact price shown before you run it. |
| Failed lookups | Handled under the vendor's own credit and refund policy. | Automatically refunded to your wallet — a search that fails upstream after billing is not charged. |
| Output format | A vendor-specific response shape you normalise and render yourself. | Normalised result panels plus the raw JSON, returned by the same POST /v1/search contract as every other integration. |
| Cross-source work | Copy-paste between vendor dashboards to follow a lead into another dataset. | Results join one case graph, so you can pivot an entity into any of the other 16 integrations in a click. |
| Running it for a team | Per-seat or per-account access, billed and administered per analyst. | One shared team wallet with roles, provider allowlists, enforced MFA, and audit history — no per-seat fee. |
| Volume work | Script the vendor API yourself, including retries, polling, and rate handling. | Bulk search takes up to 50 queries across selected providers in one submission (max 100 jobs), with per-job status and partial-failure handling. |
What every integration inherits
Good to know
Constraints worth reading before you spend a query.
A returned password or hash comes from a historical breach. It does not confirm the credential still works.
DeHashed’s site says 4.0 records are still being indexed, so a well on the public list may not be in search results yet. Figures on this page are from 22 September 2026.
The published total counts pieces of data, not unique people.
Name and IP searches are broader than email or username, so expect more noise to filter.
Going direct still makes sense at sustained high volume on a single source. DeHashed sells its own paid subscription with an API key bound to a single account. Through SearchIn you trade that commitment for per-query pricing across 17 integrations.
How to access DeHashed
Sample queries
Investigations that use DeHashed
- OSINT for cybersecurity teamsBreach, host, and identity intel on one prepaid desk — no vendor seat tax.
- OSINT for law enforcement investigationsPublic-record and commercial OSINT sources behind one search, for case support.
- OSINT for corporate risk and securityVendor, insider, and brand exposure checks without stacking OSINT subscriptions.
- OSINT for financial crime and AML opsEnrich subjects and infrastructure faster across breach, identity, and domain sources.
- OSINT for private investigatorsPeople, breach, domain, and image search without maintaining a dozen OSINT logins.
- SearchIn for OSINT analystsEvery provider behind one search — pivots, bulk jobs, and cases that stick.
- SearchIn for threat intelligence analystsInfrastructure, leaks, and actor identifiers without vendor portal fatigue.
- SearchIn for fraud investigatorsEnrich alerts and cases across identity, leaks, and domains in minutes.
Related integrations
FAQ
DeHashed on OSINTverse, answered
How do I use DeHashed in SearchIn?
Choose Email, Username, Phone, Domain, Name, or IP. Select DeHashed. Review grouped breach records and expand sensitive fields as needed.
How do I call DeHashed from the OSINTverse API?
Authenticate with an x-api-key header, then POST /v1/search with provider "dehashed" and a supported input_type (email, username, phone, domain, name, ip). Poll GET /v1/search/{id} if the job returns running.
What does DeHashed cost on SearchIn?
Email: $0.30. Username: $0.30. Phone: $0.30. Domain: $0.30. Name: $0.30. IP address: $0.30. You see the price before every run, and there is no subscription.
Why use OSINTverse instead of DeHashed directly?
DeHashed sells its own paid subscription with an API key bound to a single account. On OSINTverse you pay per query from one prepaid USD wallet with no subscription, failed searches are refunded automatically, results are normalised into a case graph you can pivot into other sources, and the same POST /v1/search contract reaches every integration. Pay $0.30 when you actually search instead of carrying a subscription between cases. Password and hash fields are masked by default with a reveal toggle — safer for screen shares and shared team workspaces. Run DeHashed, Snusbase, and LeakRadar on the same identifier in one batch to see where the datasets disagree.
What are the limits of DeHashed on SearchIn?
A returned password or hash comes from a historical breach. It does not confirm the credential still works. DeHashed’s site says 4.0 records are still being indexed, so a well on the public list may not be in search results yet. Figures on this page are from 22 September 2026. The published total counts pieces of data, not unique people. Name and IP searches are broader than email or username, so expect more noise to filter.
Run DeHashed alongside every other source
One login, one prepaid wallet, and the price shown before every lookup.
- No subscription
- Credits never expire
- Human support