Terms of Service
Effective July 26, 2026 · last updated July 26, 2026
These terms govern your use of recentbreaches.com. They are short and plain on purpose. Recent Breaches is a free news and data site — you do not need an account and we do not charge you — but the material here concerns real incidents, real companies and criminal claims, so the limits below matter.
1. Who you are dealing with
BATECH LLC operates recentbreaches.com, at 3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States. “Recent Breaches”, “GalaxyWarden” and “DoxxScan™” are trade names of BATECH LLC. In this document “we”, “us” and “our” mean BATECH LLC, and “the Site” means recentbreaches.com and the feeds, APIs and embeddable widgets we publish from it.
Recent Breaches shares an operator with galaxywarden.com. If you hold a GalaxyWarden account, the GalaxyWarden Terms of Service govern that account and your purchases; these terms govern your use of this site.
2. Acceptance
By accessing or using the Site — including reading a page, calling the API, embedding a widget, subscribing to the newsletter or consuming the RSS feed — you agree to these terms and to our Privacy Policy. If you do not agree, do not use the Site.
You must be at least 13 years old to use the Site, and at least 16 to subscribe to the newsletter.
3. What the Site is
Recent Breaches is a real-time threat-intelligence news desk. We aggregate and report on data breaches, leaks, extortion campaigns and exploited vulnerabilities from publicly accessible sources, and we publish derived material: severity classifications, verification labels, DoxxScan™ Ratings, Safety Grades, rankings, indexes and summaries.
We are not a breach-lookup registry, a credit bureau, a consumer reporting agency, or a background-check service, and nothing here may be used as a factor in any decision about a person’s credit, insurance, employment, housing or eligibility for any benefit. We do not exfiltrate, host, purchase or redistribute stolen data, and we do not hold the data claimed in leak-site listings.
The Site is free and provided as-is. We may change, suspend or discontinue any part of it — including pages, feeds, widgets and API endpoints — at any time, with or without notice.
4. No warranty as to breach information
This is the most important clause on this page, so it is in plain words as well as capitals.
A large share of the incidents we track originate from ransomware and extortion leak-site listings. Those are claims made by criminals to pressure a victim. A listing is not proof that a breach occurred, that any specific data was taken, or that the named organisation was involved at all. Record counts and data-type claims are routinely exaggerated, recycled and fabricated. Our verification label tells you how well corroborated an item is; read it before relying on anything.
Our severity levels, DoxxScan™ Ratings, Safety Grades, indexes and rankings are automated, informational estimates derived from that public reporting. They are not audits, security assessments, certifications, or statements of fact about any organisation’s security posture, and must not be relied on as such.
Some articles on the Site are drafted with AI assistance from public sources; see our editorial standards. AI-assisted text can be wrong.
WE MAKE NO WARRANTY, EXPRESS, IMPLIED OR STATUTORY, THAT BREACH INFORMATION ON THE SITE IS ACCURATE, COMPLETE, CURRENT, VERIFIED OR FIT FOR ANY PURPOSE. THE SITE, ITS CONTENT, ITS FEEDS, ITS WIDGETS AND ITS API ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTIES OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SITE WILL BE UNINTERRUPTED OR ERROR-FREE.
If you believe something here is wrong, tell us. We correct promptly and every organisation named on the Site has a standing right of reply — see §11 and our editorial standards.
5. Acceptable use
You may read, quote, link to and share what we publish. You may not:
- use the Site or its data to harass, dox, extort, defraud or threaten any person or organisation;
- use it to make decisions about credit, insurance, employment, housing or tenancy (see §3);
- scrape, crawl or automate access in a way that degrades the Site for others, or circumvent rate limiting, caching or access controls;
- republish our pages wholesale, or present our content, ratings or grades as your own;
- misrepresent our verification labels — presenting an unverified claim as a confirmed breach is specifically prohibited;
- introduce malware, attempt to gain unauthorised access to our systems, or interfere with the Site’s operation;
- use the Site in violation of any applicable law or of a third party’s rights.
We may block, rate-limit or terminate access for any of the above, at our discretion and without notice.
6. API, feeds and widgets
Our JSON API, RSS feed and embeddable widgets are documented at https://recentbreaches.com/developers. They are offered free of charge, with no key and no signup, on these terms:
- Permitted use. Personal, research, journalistic and other non-commercial use.
- Commercial use is not granted by default. A substantial part of our catalogue derives from upstream sources whose own terms restrict commercial use and redistribution. We cannot grant rights we do not hold. If you want to use the data in a commercial product or service, contact press@recentbreaches.com and we will tell you what is and is not possible.
- Attribution is required for any permitted use: a visible credit to Recent Breaches with a link to recentbreaches.com, on every surface where the data or a widget appears.
- Upstream rights survive. Records sourced from third parties remain subject to those parties’ terms and licences. The principal upstream sources are ransomware.live, Have I Been Pwned (breach data, CC BY 4.0), CISA’s Known Exploited Vulnerabilities catalog, SEC EDGAR and state Attorney General breach-notification portals. It is your responsibility to comply with them.
- Fair use of the service. Responses are cached; please cache on your side rather than polling in a tight loop. We may rate-limit, degrade or revoke access that we judge abusive, and we may change or withdraw any endpoint at any time.
Nothing in this section is a warranty of availability. Do not build anything safety-critical on a free, unauthenticated feed.
7. Newsletter
If you subscribe to the weekly recap we store your email address, the consent wording and version you agreed to, the time you agreed, and where on the Site you signed up. We use it to send the recap and, if you ticked the optional partner box, updates and offers from GalaxyWarden and its vetted partners.
We do not sell your email address. Every email carries a one-click unsubscribe link and you can unsubscribe at any time; you can also email press@recentbreaches.com. See the Privacy Policy for retention and your rights.
8. Advertising and third-party links
The Site is supported in part by advertising, currently served through Google AdSense. Ads are labelled and are not editorial endorsements; we do not let advertisers influence what we cover or how we label it. Advertising and analytics cookies only load with your consent where consent is required — see the Cookie Policy.
We link to third-party sites, including sources we cite and the GalaxyWarden services we operate. We are not responsible for third-party content, products or practices, and a link is not an endorsement.
9. Intellectual property and copyright
Our own text, page layouts, graphics, widget code, ratings, grades, indexes and compilations are owned by BATECH LLC or its licensors. Facts are not copyrightable and we do not claim them. Company names, logos and threat-actor names are the property of their respective owners and are used for identification and news-reporting purposes.
Data supplied by upstream sources remains theirs; see §6. Breach data from Have I Been Pwned is used under the Creative Commons Attribution 4.0 licence and is attributed as that licence requires.
Copyright complaints (DMCA). If you believe material on the Site infringes your copyright, send a notice to press@recentbreaches.com, or by post to BATECH LLC, 3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States, marked “DMCA Agent”. Include: identification of the work, identification of the material and its URL, your contact details, a statement that you have a good faith belief the use is unauthorised, a statement under penalty of perjury that your notice is accurate and that you are authorised to act, and your signature. We remove or disable infringing material and terminate repeat infringers. Counter-notices may be sent to the same address.
10. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, BATECH LLC AND ITS OFFICERS, MEMBERS, EMPLOYEES, CONTRACTORS AND AGENTS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY OR REPUTATION, ARISING OUT OF OR RELATING TO THE SITE OR ITS CONTENT, WHETHER IN CONTRACT, TORT OR ANY OTHER THEORY, EVEN IF WE WERE ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY TO YOU FOR ALL CLAIMS RELATING TO THE SITE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US FOR ACCESS TO THE SITE IN THE TWELVE MONTHS BEFORE THE CLAIM — WHICH, FOR A FREE SITE, IS NORMALLY ZERO — AND (B) ONE HUNDRED US DOLLARS (US$100).
Some jurisdictions do not allow the exclusion of certain warranties or the limitation of certain damages. Where that is so, the exclusions and limits above apply to the fullest extent permitted, and nothing here limits liability that cannot lawfully be limited — including for fraud or for death or personal injury caused by negligence.
11. Corrections and right of reply
Accuracy matters more to us than speed. Any organisation or person named on the Site may ask us to correct an inaccuracy, add a statement in reply, or remove personal data or a claim we cannot substantiate. Write to press@recentbreaches.com. We review promptly, publish responses above the reporting rather than deleting the reporting, and note material changes. The full process is in our editorial standards.
12. Indemnification
You agree to indemnify, defend and hold harmless BATECH LLC, its affiliates, officers, members, employees, contractors and agents from and against any claims, damages, losses, liabilities, costs and expenses (including reasonable legal fees) arising from: your use or misuse of the Site, its data, its feeds or its widgets; your breach of these terms or of any applicable law; your republication or onward use of material obtained from the Site; and your violation of any third party’s rights, including the rights of upstream data sources.
13. Governing law
These terms are governed by the laws of the State of California, United States, without regard to its conflict-of-law rules. Subject to §14, any action must be brought exclusively in the state or federal courts located in California, and you consent to their jurisdiction.
14. Disputes, arbitration and class-action waiver
Please read this section carefully — it affects how disputes between us are resolved.
Informal resolution first. Before filing anything, contact us at press@recentbreaches.com and give us 30 days to resolve it. Most things are fixable this way.
Binding arbitration. Any dispute not resolved informally will be settled by binding arbitration administered by the American Arbitration Association under its Consumer Arbitration Rules, seated in California. Judgment on the award may be entered in any court of competent jurisdiction. You and we each waive the right to a trial by jury.
CLASS-ACTION WAIVER. YOU AND WE AGREE THAT DISPUTES WILL BE RESOLVED ONLY ON AN INDIVIDUAL BASIS, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, CONSOLIDATED, COLLECTIVE OR REPRESENTATIVE ACTION. THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE PERSON’S CLAIMS OR PRESIDE OVER ANY FORM OF REPRESENTATIVE PROCEEDING.
Exceptions. Either of us may bring an individual claim in small claims court, and either of us may seek injunctive relief in court to stop infringement or misuse of intellectual property or unauthorised access to our systems. If the class-action waiver is held unenforceable as to a particular claim, that claim (and only that claim) will proceed in court.
Nothing in this section deprives you of any right you have under the mandatory consumer-protection law of your country of residence.
15. Changes to these terms
We may update these terms. The “last updated” date at the top always reflects the current version, and for material changes we will post a notice on the Site. Continuing to use the Site after a change means you accept it. If you do not accept it, stop using the Site.
16. General
If any provision is held unenforceable, the rest stays in force. Our failure to enforce a provision is not a waiver of it. You may not assign these terms; we may assign them to a successor in interest. These terms, together with the Privacy Policy and Cookie Policy, are the entire agreement between us about the Site.
17. Contact
BATECH LLC
3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States
press@recentbreaches.com · support@galaxywarden.com
General enquiries and press: https://recentbreaches.com/contact