Hacked, Breached & Leaked Data

HBL Data for Defense,
Intelligence and Law Enforcement

Shadow Nexus supplies hacked, breached and leaked (HBL) datasets and dark web PAI that never reach the open market — acquired directly through closed-source communities, resolved into attribution-grade intelligence, and delivered into your own environment.


What is HBL data?

Hacked, breached and leaked (HBL) data is the material that escapes an organization and ends up circulating privately: stolen customer and citizen databases, exfiltrated internal records, dumped credentials, scraped government systems and leaked corporate files. Combined with publicly available information (PAI), it is the richest open-source intelligence available on foreign adversary populations, because it describes people and organizations as their own systems recorded them, not as they present themselves in public.

The problem for analysts has never been whether HBL data exists. It is that the valuable material does not sit on an indexed forum waiting to be downloaded, and what does circulate publicly arrives as broken, duplicated, multi-language files that no mission system can query.

Acquisition is the differentiator

Most commercial OSINT and breach data vendors resell the same public dumps that anyone can find. Shadow Nexus tradecraft centers on the datasets that never reach a public index — private, hard-to-reach and often completely unknown collections, acquired through long-standing dark web relationships and a broad network of closed-source contacts built over years of direct work inside those communities.

That access is the reason the holdings look different from everyone else’s. It is also why a Shadow Nexus dataset frequently has no public counterpart to compare it against, and why validation and provenance are built into the delivery rather than bolted on afterwards.

Coverage

Record categories

Identity & PIIFinancialTravel & borderTelecom & cellularLaw enforcementBusiness & corporate registrySocial mediaMilitary & governmentMaritime & shippingCredentialsImmigrationVehicle & registration

Priority regions

ChinaIranRussiaVenezuelaMexicoIraqINDOPACOMTaiwanVietnamThailandSaudi Arabiaand more

How the data is delivered

On demand

Search API

Query the collection programmatically by selector — email, phone, national ID, name, document number — and pull structured records back into your own tooling.

Bulk

Direct dataset delivery

Take whole datasets or curated slices as files, cleaned and normalized, for ingest into your existing data platform on your own schedule.

In platform

Inside OcientAIQ

Through the Ocient National Security Solutions partnership, Shadow Nexus data loads straight into the OcientAIQ Unified Data Platform in cloud, on-premises, hybrid, tactical or air-gapped deployments.

What national security teams use it for

Counterintelligence and attribution

Tie an alias, a credential and a device back to a real identity across unrelated foreign breaches, and carry the finding to a source record an analyst can defend.

Vetting and force protection

Check local nationals, partners and personnel against foreign adversary holdings that no public background system contains.

Pattern of life and movement

Correlate travel, border, telecom and financial records to build movement and association pictures on denied-area targets.

Criminal and sanctions investigation

Resolve corporate and beneficial-ownership structures across jurisdictions where official registries are incomplete, closed or deliberately misleading.

You get records, not a pile of files

Raw HBL material is close to useless on arrival: mixed encodings, broken delimiters, foreign-language column headers, duplicate dumps recirculated under new names, and fabricated datasets passed off as real. Every Shadow Nexus delivery is repaired, normalized, validated for authenticity and entity-resolved before it reaches a customer.

  • Repaired and normalized — encoding, delimiter and structure problems fixed, foreign-language fields mapped to a single common schema.
  • Checked for authenticity — fabricated and synthetic datasets identified and rejected before they reach an analyst.
  • De-duplicated — recirculated dumps matched against existing holdings so you are not sold the same records twice.
  • Entity-resolved — records linked into consolidated person and organization views across datasets, languages and document types.
  • Traceable — every resolved record points back to the source dataset it came from.

That work is described in full on the data engineering page, and is available as a service against your own holdings.

Frequently asked questions

What does HBL stand for?

HBL stands for hacked, breached and leaked — data that originated inside an organization and left it without authorization, whether through intrusion, insider removal or misconfiguration. It is distinct from scraped or purchased commercial data, and distinct from publicly available information (PAI), though Shadow Nexus supplies both.

How is Shadow Nexus HBL data different from a commercial breach feed?

Commercial breach feeds are built from material that is already public, which means every customer and every adversary has the same copy. Shadow Nexus holdings come from private and closed-source communities, so a large share of the collection has no public counterpart at all. The data is also entity-resolved rather than shipped as raw dumps.

Who can buy Shadow Nexus data?

Shadow Nexus works with defense, intelligence, law enforcement, federal civilian and allied government customers, and with vetted commercial partners supporting those missions. Access is scoped to the customer and the use case.

Can the data be deployed in a classified or air-gapped environment?

Yes. Datasets can be delivered in bulk for ingest into an environment with no outbound connectivity, and through the Ocient National Security Solutions partnership they can be analyzed inside OcientAIQ in on-premises, tactical and air-gapped deployments, with data sovereignty retained by the customer.

How do I know a dataset is real?

Every dataset is assessed before delivery using intrinsic structural evidence — national identifier checksum decoding, value distribution analysis, sequential identifier detection and temporal pattern testing — and cross-referenced against known-real holdings. Fabricated and recycled datasets are rejected rather than resold.

Can Shadow Nexus collect against a specific requirement?

Yes. Alongside existing holdings, Shadow Nexus takes tasked collection requirements against specific countries, sectors, organizations or record types, and runs the same repair, validation and entity-resolution process on whatever is acquired.

Tell us the mission, not the file format

Describe the target set and the environment it has to run in, and Shadow Nexus will come back with what exists, how it would be delivered and what it would take to get it there.

Contact Shadow Nexus