Credential Reuse Exposure
Mapped a cluster of reused credentials from stealer logs and notified affected users with remediation steps.
I am KiruruSec. There is no corporate board, no profit margin to chase. Just an independent security researcher dedicated to finding data leaks, securing the internet, and protecting the unaware.
If You Received A Data Leak Alert
A KiruruSec alert is meant to help you reduce risk quickly. If credentials were exposed by an infostealer, changing passwords from the infected machine can expose the new passwords too. The alert does not require payment, and you should never send secrets or documents through public channels.
Step 1
Remove the stealer from the infected PC first, or isolate the machine and get it cleaned before using it again.
Step 2
From a clean device, change the passwords for exposed accounts and any other accounts that reused the same passwords.
Step 3
Revoke active sessions, browser sync tokens, saved passwords, API keys, and recovery methods that may have been stolen.
Step 4
Enable multi-factor authentication, preferably with an authenticator app or hardware key.
Step 5
Review recent account activity, forwarding rules, recovery email, payment methods, and connected devices.
Step 6
Watch for phishing attempts that reference the stealer infection, the leak, or ask for verification codes.
Step 7
Do not send passwords, identity documents, full logs, browser exports, or secrets through public channels.
Step 8
Contact KiruruSec if you need follow-up context about the alert you received.
Step 9
If everything is clean and the panic is over, consider buying KiruruSec a coffee so the next alert can reach someone else in time.
Support the mission →Every unit represents an individual whose data was found exposed in a leak and who received a personal alert to secure their accounts.
Operational Status
Active Scanning
Last Audit Log Update
2026-08-10 13:51 Europe/Rome
Syncing with scanning node #09...
Many assume KiruruSec is an agency. It's not.
I spend my nights scanning the darker corners of the internet. My goal isn't to exploit findings for money, but to close the holes before bad actors find them.
When a leak is found, time is critical. I work to alert the affected company and individuals immediately. No ransom, no threats—just remediation.
"Security is a process, not a product. I am here to help facilitate that process for those who cannot afford enterprise defense."
"My goal is not to profit from fear, but to provide a shield for the digital world."
I am Salvatore Ansani, the human behind KiruruSec. I operate as a solo, independent security researcher. This is not a business; it is my personal contribution to a safer internet.
I dedicate a significant portion of my time to pro-bono research, specifically focusing on data leaks. I hunt for exposed databases and vulnerabilities not for financial gain, but to protect unsuspecting victims who often have no idea their private information is at risk.
When I discover a breach, I personally reach out to notify the victims and guide organizations through responsible disclosure, ensuring the gap is closed before malicious actors can exploit it.
"Privacy is a human right, not a subscription service."
I believe that high-quality security research should benefit everyone, not just those with deep pockets. My philosophy centers on Radical Transparency and Altruistic Defense.
KiruruSec is entirely self-funded. I do not sell data, I do not charge victims for alerts, and I do not work for corporate bounty platforms. My reward is the closure of a vulnerability and the safety of the community. Support through donations simply helps keep my scanning infrastructure running.
A log of significant vulnerabilities I have identified and helped resolve.
Correlated exposed credentials from fresh infostealer logs, prioritized high-risk accounts, and sent remediation guidance to affected victims.
Identified exposed documents in a public storage bucket and routed a minimal-evidence report through responsible disclosure channels.
Found a portal exposure affecting personal account data and worked through disclosure steps focused on containment and victim notification.
Archive
An anonymized timeline of previous leak triage, exposed-data reports, and remediation support. Entries avoid naming affected organizations unless disclosure is already public.
Mapped a cluster of reused credentials from stealer logs and notified affected users with remediation steps.
Identified an exposed backup snapshot containing internal files and guided the owner through access restriction.
Reported an internet-facing administrative interface before sensitive operations could be abused.
Found active-looking session material in a public leak source and recommended immediate token rotation.
Detected documents exposed through directory listing and escalated a minimal-evidence disclosure report.
Traced exposed customer references to a vendor system and helped route the report to the correct contacts.
Identified a publicly searchable data index and documented the exposure path for responsible disclosure.
Filtered fresh credential material, removed obvious noise, and prioritized direct alerts for high-risk victims.
Found cached API responses containing personal data and reported the issue with reproduction boundaries.
Reported public application logs that revealed internal paths, identifiers, and account-related metadata.
Identified an unauthenticated file share and coordinated disclosure without downloading unnecessary material.
Correlated exposed phishing-kit artifacts with affected accounts and sent practical containment guidance.
Started the 2024 archive with a reviewed batch of exposed account data, prioritizing cleanup and notification.
No. KiruruSec is just me—an independent security researcher. I don't have a marketing team or a sales department. My focus is purely on research and internet safety.
Absolutely not. My mission is ethical. When I find a leak, I notify the affected parties and, if possible, the victims. I never sell or trade data.
Since I do this pro-bono, donations help cover scanning nodes, email delivery, storage, and the time required to contact victims. You can support me via PayPal, Buy Me a Coffee, or Ko-fi. Data leak alerts remain free and a donation is always optional.
I am open to consulting or private audits. Please join the Discord server or send an email to discuss potential collaboration.
Independent research requires time, servers, storage, email delivery, and coffee. If my work has helped you, or if you believe in a safer internet, consider supporting the mission.
Best for direct one-time donations after a data leak alert helped you secure an account.
Donate via PayPal →A quick way to support late-night checks, responsible disclosure, and victim notification work.
Support on Buy Me a Coffee →Useful if you prefer small recurring or one-time support for infrastructure and alert operations.
Support on Ko-fi →Trust & Ethics
KiruruSec is built around victim notification and responsible disclosure. Donations cover operational costs, but they do not buy leaked data, special access, or disclosure priority.
Data leak alerts are free.
Donations are optional.
No data sale, no ransom, no access brokerage.
Responsible disclosure comes before publicity.
Sensitive evidence should be handled by email first.
Contact
Use this page for security reports, data leak follow-up, collaboration requests, or urgent remediation contacts. Do not send passwords, ID documents, full database dumps, API keys, private keys, or secrets through public channels.
[email protected]
Best for responsible disclosure details, indicators, logs, and follow-up context.
+393792558512
For urgent responsible disclosure or remediation follow-up.
Discord
Join the community
For public discussion, community alerts, and coordination.
1. Responsible disclosure
Use email first so technical evidence and timelines stay clear.
2. Urgent remediation
Use WhatsApp only when timing is critical and a live contact is needed.
3. Community
Use Discord for public coordination, not for sharing sensitive evidence.
Scope
Security reports, exposed data, misconfigurations, and alert follow-up.
Preferred channel
Sensitive material
Share minimum evidence first. Do not send secrets through Discord or WhatsApp.
A public security.txt file is available at /.well-known/security.txt.