otherAugust 26, 2026Issue #95

Troy Hunt's data-breach claims: the verification trap

Troy Hunt — the guy behind Have I Been Pwned and the person who tracks breaches like a hawk — just wrote a post about what happens when his breach-claim pages get hit by a flood of requests. His API returns a 412 if you're brute-forcing or scraping. The problem: people are hitting it with thousands of emails in bulk, trying to harvest which accounts have been exposed. Hunt says the 412 is working as intended, but the volume is so high it's clogging up legitimate users and making the service harder to use for the people who need it.

The real story here isn't the 412 itself — it's the economics of breach data. The 2024–2025 wave of claims is massive, and there's an entire cottage industry of people selling breach lists, scraping them, or building tools to search them. Hunt's API is one of the few trusted sources, which makes it a target. The tradeoff is real: if you lock it down too hard, legitimate people can't check their own emails. If you leave it open, you get flooded and the service degrades for everyone.

Why this matters for us:
When the tools we rely on get attacked at scale, the people who need them most — the folks checking whether their work email leaked — are the ones who pay the price.

The 412 is doing its job. The flood isn't.

troyhunt.com

Read the originalOpen in new tab
#breach-verification#api-abuse#security#troy-hunt

Daily issue · no spam

Get the daily on your stoop

One short email a day — AI, tech, and what it means for our communities. Plain language, cultural lens, no Silicon Valley jargon.