Active Monitoring & Research

ONE MAN.
ZERO COMPROMISE.

I am KiruruSec. There is no corporate board, no profit margin to chase. Just an independent security researcher dedicated to finding data leaks, securing the internet, and protecting the unaware.

If You Received A Data Leak Alert

Remove the stealer first. Then secure the accounts from a clean device.

A KiruruSec alert is meant to help you reduce risk quickly. If credentials were exposed by an infostealer, changing passwords from the infected machine can expose the new passwords too. The alert does not require payment, and you should never send secrets or documents through public channels.

Step 1

Remove the stealer from the infected PC first, or isolate the machine and get it cleaned before using it again.

Step 2

From a clean device, change the passwords for exposed accounts and any other accounts that reused the same passwords.

Step 3

Revoke active sessions, browser sync tokens, saved passwords, API keys, and recovery methods that may have been stolen.

Step 4

Enable multi-factor authentication, preferably with an authenticator app or hardware key.

Step 5

Review recent account activity, forwarding rules, recovery email, payment methods, and connected devices.

Step 6

Watch for phishing attempts that reference the stealer infection, the leak, or ask for verification codes.

Step 7

Do not send passwords, identity documents, full logs, browser exports, or secrets through public channels.

Step 8

Contact KiruruSec if you need follow-up context about the alert you received.

Step 9

If everything is clean and the panic is over, consider buying KiruruSec a coffee so the next alert can reach someone else in time.

Support the mission →

Real-time Impact Tracking

4,352,815Victims Notified

Every unit represents an individual whose data was found exposed in a leak and who received a personal alert to secure their accounts.

Operational Status

Active Scanning

Last Audit Log Update

2026-08-10 13:51 Europe/Rome

Syncing with scanning node #09...

NOT A COMPANY. A COMMITMENT.

Many assume KiruruSec is an agency. It's not.

🕵️‍♂️ The Researcher

I spend my nights scanning the darker corners of the internet. My goal isn't to exploit findings for money, but to close the holes before bad actors find them.

  • Pro-bono Research
  • Ethical Disclosure
  • Victim Notification

🛡️ The Protection

When a leak is found, time is critical. I work to alert the affected company and individuals immediately. No ransom, no threats—just remediation.

"Security is a process, not a product. I am here to help facilitate that process for those who cannot afford enterprise defense."

BEHIND THE MASK

"My goal is not to profit from fear, but to provide a shield for the digital world."

Salvatore Ansani

I am Salvatore Ansani, the human behind KiruruSec. I operate as a solo, independent security researcher. This is not a business; it is my personal contribution to a safer internet.

I dedicate a significant portion of my time to pro-bono research, specifically focusing on data leaks. I hunt for exposed databases and vulnerabilities not for financial gain, but to protect unsuspecting victims who often have no idea their private information is at risk.

When I discover a breach, I personally reach out to notify the victims and guide organizations through responsible disclosure, ensuring the gap is closed before malicious actors can exploit it.

#SalvatoreAnsani#Independent#Non-Profit#DataProtection#CyberSentinel

My Philosophy

"Privacy is a human right, not a subscription service."

I believe that high-quality security research should benefit everyone, not just those with deep pockets. My philosophy centers on Radical Transparency and Altruistic Defense.

Zero Profit Mission

KiruruSec is entirely self-funded. I do not sell data, I do not charge victims for alerts, and I do not work for corporate bounty platforms. My reward is the closure of a vulnerability and the safety of the community. Support through donations simply helps keep my scanning infrastructure running.

MAJOR DATA LEAKS

A log of significant vulnerabilities I have identified and helped resolve.

View Archive
Active Victim Notifications2026-08-05

Infostealer Credential Exposure Wave

Correlated exposed credentials from fresh infostealer logs, prioritized high-risk accounts, and sent remediation guidance to affected victims.

VERIFIED & SECURED
Sensitive Files2026-07-28

Public Cloud Storage Misconfiguration

Identified exposed documents in a public storage bucket and routed a minimal-evidence report through responsible disclosure channels.

VERIFIED & SECURED
Account Risk2026-07-14

Customer Portal Data Exposure

Found a portal exposure affecting personal account data and worked through disclosure steps focused on containment and victim notification.

VERIFIED & SECURED

Archive

Historical disclosure and victim notification work.

An anonymized timeline of previous leak triage, exposed-data reports, and remediation support. Entries avoid naming affected organizations unless disclosure is already public.

2026-06-19Account Takeover Risk

Credential Reuse Exposure

Mapped a cluster of reused credentials from stealer logs and notified affected users with remediation steps.

2026-04-24Backup Files

Public Backup Snapshot

Identified an exposed backup snapshot containing internal files and guided the owner through access restriction.

2026-02-12Admin Exposure

Misconfigured Admin Panel

Reported an internet-facing administrative interface before sensitive operations could be abused.

2025-12-09Session Risk

Leaked Session Token Set

Found active-looking session material in a public leak source and recommended immediate token rotation.

2025-10-17Indexed Documents

Open Directory Data Spill

Detected documents exposed through directory listing and escalated a minimal-evidence disclosure report.

2025-08-23Supply Chain

Third-Party Vendor Exposure

Traced exposed customer references to a vendor system and helped route the report to the correct contacts.

2025-06-12Searchable Records

Database Index Misconfiguration

Identified a publicly searchable data index and documented the exposure path for responsible disclosure.

2025-04-26Victim Alerts

Credential Dump Triage

Filtered fresh credential material, removed obvious noise, and prioritized direct alerts for high-risk victims.

2025-02-16Personal Data

Exposed API Response Cache

Found cached API responses containing personal data and reported the issue with reproduction boundaries.

2024-04-11Operational Logs

Public Log File Exposure

Reported public application logs that revealed internal paths, identifiers, and account-related metadata.

2024-03-22Shared Files

Unprotected File Share

Identified an unauthenticated file share and coordinated disclosure without downloading unnecessary material.

2024-02-15Victim Follow-Up

Phishing Kit Evidence Trail

Correlated exposed phishing-kit artifacts with affected accounts and sent practical containment guidance.

2024-01-19Initial Triage

January Leak Intake Review

Started the 2024 archive with a reviewed batch of exposed account data, prioritizing cleanup and notification.

PROTOCOL & QUERY

Are you a company?

No. KiruruSec is just me—an independent security researcher. I don't have a marketing team or a sales department. My focus is purely on research and internet safety.

Do you sell the data you find?

Absolutely not. My mission is ethical. When I find a leak, I notify the affected parties and, if possible, the victims. I never sell or trade data.

How can I support your work?

Since I do this pro-bono, donations help cover scanning nodes, email delivery, storage, and the time required to contact victims. You can support me via PayPal, Buy Me a Coffee, or Ko-fi. Data leak alerts remain free and a donation is always optional.

Can I hire you?

I am open to consulting or private audits. Please join the Discord server or send an email to discuss potential collaboration.

KEEP THE LIGHTS ON

Independent research requires time, servers, storage, email delivery, and coffee. If my work has helped you, or if you believe in a safer internet, consider supporting the mission.

PayPal

PayPal

Best for direct one-time donations after a data leak alert helped you secure an account.

Donate via PayPal →
Buy Me a Coffee

Buy Me a Coffee

A quick way to support late-night checks, responsible disclosure, and victim notification work.

Support on Buy Me a Coffee →
Ko-fi

Ko-fi

Useful if you prefer small recurring or one-time support for infrastructure and alert operations.

Support on Ko-fi →

Trust & Ethics

Support helps the mission. It never changes the disclosure rules.

KiruruSec is built around victim notification and responsible disclosure. Donations cover operational costs, but they do not buy leaked data, special access, or disclosure priority.

Data leak alerts are free.

Donations are optional.

No data sale, no ransom, no access brokerage.

Responsible disclosure comes before publicity.

Sensitive evidence should be handled by email first.

Contact

Responsible disclosure, urgent contacts, and community.

Use this page for security reports, data leak follow-up, collaboration requests, or urgent remediation contacts. Do not send passwords, ID documents, full database dumps, API keys, private keys, or secrets through public channels.

Contact priority

1. Responsible disclosure

Use email first so technical evidence and timelines stay clear.

2. Urgent remediation

Use WhatsApp only when timing is critical and a live contact is needed.

3. Community

Use Discord for public coordination, not for sharing sensitive evidence.

Responsible disclosure policy

Scope

Security reports, exposed data, misconfigurations, and alert follow-up.

Preferred channel

[email protected]

Sensitive material

Share minimum evidence first. Do not send secrets through Discord or WhatsApp.

A public security.txt file is available at /.well-known/security.txt.

%