Breach intelligence

LeakOSINTbot OSINT integration

Breach-database style leak search for emails, usernames, phones, domains, and IPs.

LeakOSINTbot returns hits organized by breach database — each database lists records with flexible fields plus aggregate result counts. On 23 September 2026 the service reported 10,750 databases loaded and 110,125,319,231 records, and said it adds databases every day.

Capabilities
What this integration is designed to return.
Search by email, username, phone, domain, or IP
Group findings by breach / dump name
Surface passwords, URLs, and other leak fields when the dump stored them
10,750 databases and 110,125,319,231 records loaded (snapshot 23 September 2026)
Best for
Typical investigation fits.
Quick leak corpus lookups
Complementing LeakRadar credential views
Investigators who need dump-level provenance

How the LeakOSINTbot integration works

What happens between pressing run and reading a result.

  1. 1Choose email, username, phone, domain, or IP and select LeakOSINTbot.
  2. 2SearchIn issues the lookup over an authenticated HTTP call — no Telegram session on your side.
  3. 3Findings come back grouped by breach database, each with the fields that dump happens to carry.
  4. 4SearchIn renders collapsible database sections with secret masking, plus upstream counts and totals.
Data coverage
What the underlying dataset reaches.

On 23 September 2026 LeakOSINT reported 10,750 databases loaded and 110,125,319,231 records, and said new databases are added every day. SearchIn queries that corpus by email, username, phone, domain, or IP.

Data sources

SearchIn queries LeakOSINT by email, username, phone, domain, or IP. The service said these databases were loaded on 23 September 2026, and that it adds databases every day. The field list is what those databases contain, not a list of SearchIn search boxes.

Databases loaded
10,750
Records
110.13 billion

The exact figure is 110,125,319,231 records. That is a record count, not a count of unique people. Field totals below are stored values, and one record can hold several fields.

Snapshot
23 September 2026
Email
29,017,977,376

SearchIn input

Email is a SearchIn query. A hit returns the databases that stored this address.

Telephone
16,664,522,678

SearchIn input

Phone is a SearchIn query. LeakOSINT calls this field Telephone.

Nick
12,533,362,032

SearchIn input

Username search looks for handles. LeakOSINT stores those as Nick, separate from Login.

IP
1,866,978,034

SearchIn input

IP address is a SearchIn query.

Domain
84,443,729

SearchIn input

Domain is a SearchIn query.

Full name
18,174,239,687

Stored field

Names sit on records. SearchIn does not take a name as the LeakOSINT query.

Password
14,776,343,285

Stored field

Passwords appear on a row when the dump stored one. A password is historical, not proof it still works.

Passport number
3,016,946,855

Stored field

Stored on some records. Not a SearchIn query input.

Link
2,603,204,738

Stored field

URLs stored next to a matching identifier. Not a SearchIn query input.

VK ID
1,898,415,438

Stored field

Stored on some records. Not a SearchIn query input.

Document number
1,751,997,597

Stored field

Stored on some records. Not a SearchIn query input.

Steam ID
989,145,687

Stored field

Stored on some records. Not a SearchIn query input.

SSN
933,835,461

Stored field

Stored on some records. Not a SearchIn query input.

Taxpayer number
867,649,114

Stored field

Stored on some records. Not a SearchIn query input.

Company name
826,516,135

Stored field

Stored on some records. Not a SearchIn query input.

Facebook ID
766,261,868

Stored field

Stored on some records. Not a SearchIn query input.

Car number
759,740,851

Stored field

Stored on some records. Not a SearchIn query input.

SNILS number
732,793,903

Stored field

Stored on some records. Not a SearchIn query input.

Contact person
628,374,856

Stored field

Stored on some records. Not a SearchIn query input.

VIN
576,616,008

Stored field

Stored on some records. Not a SearchIn query input.

Login
297,856,649

Stored field

A separate login field from Nick. SearchIn username search is the handle query, not this column.

Telegram ID
167,326,991

Stored field

Stored on some records. Not a SearchIn query input.

App
143,795,442

Stored field

Mobile or desktop application names stored on some records.

Instagram identifier
46,974,817

Stored field

Stored on some records. Not a SearchIn query input.

What a SearchIn query returns
The counts are the loaded corpus. A query returns matches for one identifier.
Rows come back grouped by database, with only the fields that dump stored.
Password fields stay masked until you reveal them.
A password on a row is historical. It does not show the credential still works.
Passport, document, taxpayer, SNILS, SSN, vehicle, and social ids can appear on a record. SearchIn does not take them as the search.

Supported inputs & pricing

Prices are USD. LeakRadar includes 1,000 credential unlocks in the query price, then $0.50 per extra 1,000. OSINT Industries is $0.60 plus optional premium modules at $1.80. Other integrations are flat per query. Full SearchIn rates are on pricing.

LeakOSINTbot SearchIn pricing by input type
Input typePrice
Emailemail$0.20
Usernameusername$0.20
Phonephone$0.20
Domaindomain$0.20
IP addressip$0.20

Why run LeakOSINTbot through OSINTverse

You can always buy LeakOSINTbot directly. Here is what changes when the same data comes through SearchIn instead. Full write-up: OSINTverse vs LeakOSINTbot.

At $0.20 it is the cheapest sweep on the desk — run it first, then spend on LeakRadar or DeHashed only if it hits.

Results arrive as searchable, collapsible database sections in the browser instead of a chat log you scroll.

Available over the same POST /v1/search contract as every other integration, so it automates like the rest.

LeakOSINTbot directly compared with LeakOSINTbot through OSINTverse SearchIn
 LeakOSINTbot directlyThrough OSINTverse
Getting startedLeakOSINTbot is operated through its own Telegram bot with token top-ups, and responses arrive as chat messages.Sign in, top up from $10, and run LeakOSINTbot the same minute — no vendor contract, seat, or sales call.
What a query costsPlan, credit pack, or contract pricing set by the vendor and paid up front.Pay per query from your prepaid balance — LeakOSINTbot starts at $0.20 for email lookups, with the exact price shown before you run it.
Failed lookupsHandled under the vendor's own credit and refund policy.Automatically refunded to your wallet — a search that fails upstream after billing is not charged.
Output formatA vendor-specific response shape you normalise and render yourself.Normalised result panels plus the raw JSON, returned by the same POST /v1/search contract as every other integration.
Cross-source workCopy-paste between vendor dashboards to follow a lead into another dataset.Results join one case graph, so you can pivot an entity into any of the other 16 integrations in a click.
Running it for a teamPer-seat or per-account access, billed and administered per analyst.One shared team wallet with roles, provider allowlists, enforced MFA, and audit history — no per-seat fee.
Volume workScript the vendor API yourself, including retries, polling, and rate handling.Bulk search takes up to 50 queries across selected providers in one submission (max 100 jobs), with per-job status and partial-failure handling.

What every integration inherits

One wallet, no subscriptions
Top up prepaid USD from $10 and spend it a query at a time across all 17 integrations. No monthly fee, no seat count — and the balance never expires.
Failed searches are refunded
If an upstream provider errors or times out after the charge, the search is marked refunded and the money goes back to your wallet automatically.
One API for every source
The same POST /v1/search contract and x-api-key header work for every integration, so adding a source to your automation is a one-word change.
Cases and pivot graph
Results land in a named case you can reopen. Entities become graph nodes you can pivot from into any other integration without retyping.
Team wallets and controls
Share one balance with roles, provider allowlists, enforced MFA, and audit history — instead of buying a vendor seat for every analyst.
Exports built in
Download any result as JSON, CSV, or PDF, and export the case graph as PNG, SVG, entities CSV, or graph JSON.

Good to know

Constraints worth reading before you spend a query.

Field shapes vary by source dump — records render flexibly rather than against a fixed schema.

SearchIn queries email, username, phone, domain, and IP only. Name, password, passport, document, taxpayer, SNILS, SSN, vehicle, and social ids are stored fields, not search inputs.

The 10,750 databases and field counts are a 23 September 2026 snapshot. LeakOSINT says it adds databases every day.

Provenance is only as good as the upstream corpus; corroborate before acting on a record.

Going direct still makes sense at sustained high volume on a single source. LeakOSINTbot is operated through its own Telegram bot with token top-ups, and responses arrive as chat messages. Through SearchIn you trade that commitment for per-query pricing across 17 integrations.

How to access LeakOSINTbot

Access via SearchIn UI
Run the integration without leaving the dashboard.
  1. Choose Email, Username, Phone, Domain, or IP.
  2. Select LeakOSINTbot.
  3. Browse databases, expand records, and copy fields as needed.

What you'll see

  • ·Collapsible database sections
  • ·Per-field rows with secret masking
  • ·Search filter across returned databases
  • ·Upstream search metadata when available
Open with this integration
Access via API
Authenticate with x-api-key, then create a search job.

Use POST /v1/search with provider leakosintbot. Poll GET /v1/search/{id} when status is running (FaceCheck).

curl -X POST "https://apiv1.osintverse.com/v1/search" \
  -H "Content-Type: application/json" \
  -H "x-api-key: ov_your_api_key" \
  -d '{"provider":"leakosintbot","input_type":"username","query":"hackru"}'

Sample queries

username
hackru
Handle across leak DBs
email
hackru@gmail.com
Email-centric dumps
phone
+15550001111
Phone-linked leak records
domain
example.com
Domain-wide leak corpus
ip
203.0.113.10
IP-linked leak records

Investigations that use LeakOSINTbot

FAQ

LeakOSINTbot on OSINTverse, answered

How do I use LeakOSINTbot in SearchIn?

Choose Email, Username, Phone, Domain, or IP. Select LeakOSINTbot. Browse databases, expand records, and copy fields as needed.

How do I call LeakOSINTbot from the OSINTverse API?

Authenticate with an x-api-key header, then POST /v1/search with provider "leakosintbot" and a supported input_type (email, username, phone, domain, ip). Poll GET /v1/search/{id} if the job returns running.

What does LeakOSINTbot cost on SearchIn?

Email: $0.20. Username: $0.20. Phone: $0.20. Domain: $0.20. IP address: $0.20. You see the price before every run, and there is no subscription.

Why use OSINTverse instead of LeakOSINTbot directly?

LeakOSINTbot is operated through its own Telegram bot with token top-ups, and responses arrive as chat messages. On OSINTverse you pay per query from one prepaid USD wallet with no subscription, failed searches are refunded automatically, results are normalised into a case graph you can pivot into other sources, and the same POST /v1/search contract reaches every integration. At $0.20 it is the cheapest sweep on the desk — run it first, then spend on LeakRadar or DeHashed only if it hits. Results arrive as searchable, collapsible database sections in the browser instead of a chat log you scroll. Available over the same POST /v1/search contract as every other integration, so it automates like the rest.

What are the limits of LeakOSINTbot on SearchIn?

Field shapes vary by source dump — records render flexibly rather than against a fixed schema. SearchIn queries email, username, phone, domain, and IP only. Name, password, passport, document, taxpayer, SNILS, SSN, vehicle, and social ids are stored fields, not search inputs. The 10,750 databases and field counts are a 23 September 2026 snapshot. LeakOSINT says it adds databases every day. Provenance is only as good as the upstream corpus; corroborate before acting on a record.

Run LeakOSINTbot alongside every other source

One login, one prepaid wallet, and the price shown before every lookup.

  • No subscription
  • Credits never expire
  • Human support