TL;DR: DeHashed is a commercial search engine over personal data exposed in past breaches. Its own terms say the data is collected automatically from public sources and is not verified, and they rule out screening anyone for credit, insurance, employment or housing. Legality depends on the jurisdiction, on what is searched, and on what is done with the result. Checking your own record raises none of the harder questions. This guide describes what the statutes and terms say, and is not legal advice.

What DeHashed Actually Is

DeHashed describes itself, in its own terms of service, as a "Data-Mining and Deep Web Asset Search Engine" [1]. Its homepage is plainer: "We collect sensitive data that's been posted on the clear-web & deep-web, allowing users to search for usernames, email addresses, IP addresses, and more" [2]. Access is sold to registered account holders, who must be at least 18 [1]. Pricing is tiered, though the structure could not be confirmed against the company's current site.

Two sentences in those terms do more work than the marketing pages: "All data offered is derived from public sources automatically", and "DeHashed does not verify or evaluate each piece of data" [1]. A hit is a record that appeared somewhere a collector reached, not a finding the company stands behind.

DeHashed says it is "trusted by thousands of law enforcement agencies and Fortune 500 companies" [2], its own claim rather than an audited count. Two things could not be established here: whether DeHashed has itself been breached, and whether it is registered under any state's data broker law. Neither absence is evidence either way.

How It Differs From Have I Been Pwned

The difference is structural. HIBP's API documentation states that "By default, only the name of the breach is returned rather than the complete breach data", and that "There are no API endpoints that return the password for a user" [3]. Its password check never receives the password: "Your password is hashed locally and only the first 5 characters of the SHA-1 hash are sent to the API" [4].

No equivalent mechanism is described on the DeHashed pages reviewed here, an absence in the material checked rather than a statement about the service's internals. This site's earlier guide and its dark-web OSINT piece both report that DeHashed returns the underlying exposed records, including plaintext passwords where the source data contains them [16][17], carried here as prior reporting rather than re-verified.

Is Searching It Legal? Three Layers, No Single Answer

Any one-word verdict compresses three questions: whether you are authorised to use the tool, what you search and why, and what you do with the result. Answers differ by jurisdiction.

United States

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, criminalises accessing a protected computer "without authorization or exceeds authorized access" and obtaining information from it [5]. In Van Buren v. United States (2021), the Supreme Court read that second phrase narrowly. The Congressional Research Service's summary states the provision "does not cover those who...have improper motives for obtaining information that is otherwise available to them" [6]. The test is gates-up-or-down: it reaches someone who gets into files they cannot access at all, not someone who misuses access they legitimately hold.

An account holder searching an index on the terms its operator sold them is therefore unlikely to be committing a CFAA offence against that operator by searching. The exposure sits downstream: using a password found there to log into someone else's account is unauthorised access to that system, which the CFAA reaches directly. Footnote eight of the opinion, the Congressional Research Service notes, "seemingly left open" whether contractual restrictions on the scope of accessible information could still matter [6].

United Kingdom

Section 1 of the Computer Misuse Act 1990 requires, for an offence, that a person cause a computer to perform a function intending to secure access to data where "the access he intends to secure, or to enable to be secured, is unauthorised", knowing at the time that this is so [7]. The structure resembles the CFAA's "without authorization" prong.

EU and UK GDPR

This layer is compliance rather than criminal law, and most discussions skip it. Searching for an identifiable other person's data is processing of personal data, which under Article 6(1) needs one of six lawful bases; the data having already leaked does not supply one. The nearest candidate for a private individual is Article 6(1)(f), legitimate interests, which yields where overridden by "the interests or fundamental rights and freedoms of the data subject" [8]. Article 2(2)(c) offers a wider exit, placing processing "by a natural person in the course of a purely personal or household activity" outside the regulation entirely [9].

How far that exemption stretches is open. Explaining the same GDPR-derived concept, the Irish Data Protection Commission says it does not apply where data is "used in connection with a professional or commercial activity or made publicly available" [10]. That is one EU regulator on a shared concept, not a UK regulator's position, and no case law on curiosity-searching a third party inside a breach aggregator was located. Unsettled is not the same as permitted.

Checking your own record sidesteps this layer entirely: you are the data subject.

What the Terms Themselves Rule Out

DeHashed does its own gatekeeping. Account holders may not use the service "to evaluate a consumer's eligibility for credit or insurance", nor "to evaluate a person's eligibility for employment or...renting a dwelling" [1]. Those are the uses the US Fair Credit Reporting Act regulates: the carve-out is the company declining to be treated as a consumer reporting agency.

Why such carve-outs exist is on the public record, in a case about a different company. In June 2012 the Federal Trade Commission settled charges against the people-search service Spokeo, which had marketed consumer profiles to employers and recruiters without meeting FCRA obligations. The FTC called it "the first Commission case to address the sale of Internet and social media data in the employment screening context" [11]. Spokeo is not DeHashed, and no enforcement action against DeHashed was located, but the case is the precedent those terms are written against.

Why This Is a Surveillance Story

A breach is supposed to be an event that decays: disclosed, patched, passwords changed, the file gradually worthless. Aggregation breaks that curve. Indexing thousands of incidents into one queryable corpus turns transient exposures into a permanent searchable record of who a person was and which services they used, long after every company involved has moved on. That is a data broker function, performed on material nobody consented to publish.

Investigators document its usefulness themselves. Bellingcat's toolkit tells its researchers that DeHashed, "ostensibly designed for individuals and companies to detect and monitor data breaches in real time", can also serve open-source research, and warns them: "do not try to log in to any person's account, this is unethical!" [15]. A corpus built so people can find their own exposure works equally as a lookup index for everyone else's.

Prosecutors have pursued operators in this space. In May 2022 the US Department of Justice announced the seizure of the domain weleakinfo.to, which it said "provided its users a search engine to review and obtain the personal information illegally obtained in over 10,000 data breaches containing seven billion indexed records" [12]. That was a different service, and the distinction turned on the data's provenance. On DeHashed, the threat-intelligence group Curated Intelligence concluded in 2021 that "their legal status remains unclear...legal trouble is plausible" [14], an opinion rather than a court or regulator finding.

Checking Your Own Exposure

Federal guidance is direct about what a confirmed hit should trigger. NIST Special Publication 800-63B tells verifiers they "SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)", but "SHALL force a change if there is evidence of compromise of the authenticator" [13]. It also says new passwords should be screened against lists that may include "Passwords obtained from previous breach corpuses" [13].

That reframes the exercise. Calendar-based rotation is the habit NIST advises against; finding your own credential in a corpus is the evidence of compromise that should force a change, on that account and anywhere it was reused. But a clean search is not a clean bill of health, on the service's own account of its sourcing [1], and a hit is a record from an unverified corpus, useful as a prompt and not as proof of anything further. This site's guide to finding your leaked data online covers the wider set of checking tools [16], and its dark-web OSINT piece covers the infostealer economy that keeps refilling corpora like this one [17].

Sources

  1. DeHashed: Terms of Service and Privacy Policy (undated)
  2. DeHashed: homepage marketing copy (undated, self-reported)
  3. Have I Been Pwned: API v3 documentation (undated)
  4. Have I Been Pwned: Pwned Passwords and k-anonymity (undated)
  5. 18 U.S.C. § 1030, Computer Fraud and Abuse Act, statutory text (Office of the Law Revision Counsel)
  6. Congressional Research Service, Legal Sidebar LSB10616: "Van Buren v. United States: Supreme Court Holds Accessing Information on a Computer for Unauthorized Purposes Not Federal Crime" (July 1, 2021)
  7. Computer Misuse Act 1990, Section 1 (legislation.gov.uk)
  8. GDPR Article 6: lawfulness of processing (consolidated text)
  9. GDPR Article 2: material scope (consolidated text)
  10. Irish Data Protection Commission: "What is the household exemption?" (undated FAQ)
  11. Federal Trade Commission: "Spokeo to Pay $800,000 to Settle FTC Charges Company Allegedly Marketed Information to Employers and Recruiters in Violation of FCRA" (June 12, 2012)
  12. U.S. Department of Justice, U.S. Attorney's Office for the District of Columbia: "weleakinfoto and related domain names seized" (May 31, 2022)
  13. NIST Special Publication 800-63B, Digital Identity Guidelines, section 5.1.1.2
  14. Curated Intelligence: "Assessing the state of breached data search services" by Trevor Giffen, edited by Steve Ragan (March 21, 2021)
  15. Bellingcat Online Investigation Toolkit: DeHashed tool page (undated)
  16. State of Surveillance: Find Your Leaked Data Online: The Complete Guide
  17. State of Surveillance: Dark Web OSINT: Finding Your Leaked Data Before Criminals Do