Skip to content
← UserSearch.comLog in ↗

Reading Leaks & breaches results

Running a Public Leaks search populates the Search Results panel on the right of the composer. This page explains how to read and verify that result set. Leaks results follow the same reading model as every Search type, so this page leans on the general Found, Enriched & Connections concept for the shared mechanics and calls out what is specific to breach data.

Every populated results header carries the same trio of counters, in this order, counting three different things (never interchange them):

  • Found (green) — the identifier was located in a data source. For a leak search this means your value appears in that source’s leak/breach data.
  • Enriched (orange) — UserSearch holds further metadata on that hit (such as associated names or linked identifiers). Enriched is a strict subset of Found.
  • Connections (white) — relationships/links surfaced between entities, intended to populate the Connections graph.

See The three counters for the full definitions and captured examples.

The results panel has Search Results and Bookmarks tabs. Its header pins the Found / Enriched / Connections counter tiles top-right, and offers action buttons — AI Analyse, AI Ask, Export and Clear — plus (in some states) a Filter control that narrows the visible rows.

The results table adapts its columns to the Module that produced them:

  • For a single-source leak Module (such as IntelX), expect a per-source column layout built around the found sites/hits.
  • For OneScan, expect a Data Source column that attributes each row to the specific leak source it came from — the value of running a multi-source scan.

Selecting a row drives the Details panel below the table. It organises the row’s structured detail into tabs (Details, optionally Profile View, and Graph) and, within the Details tab, a stack of labelled sub-sections — a search summary, connection tables, and, where a hit is enriched, an INFORMATION block carrying the enrichment metadata. For the full anatomy see The Details panel.

  • A Found result confirms the identifier appears in that data source’s leak data — it is that source’s report of an exposure, not independent proof of a live account.
  • Any Match Accuracy figure shown is set by the third-party data source, not computed by UserSearch (per Lee, 2026-07-08). Treat it as that source’s own confidence figure.
  • Cross-check exposures across Modules: an IntelX hit and a HaveIBeenPwned hit for the same value corroborate each other. Running OneScan does this cross-checking in one pass, with the Data Source column showing which sources agree.
  • Use the Google “G” pivot icon beside a searched value to open Google with a preset dork for that value (per Lee, 2026-07-08) and pursue the exposure further.

Verified against UserSearch v2.0.20