# Data Breach Detector Muse connector

From musedirectory.ai, the independent directory of Meta Muse connectors. Not affiliated with Meta.

## Data Breach Detector

Check if your company or domain has been in a public data breach, with full history back to 2007.

- Record: https://musedirectory.ai/connector/data-breach-detector
- Category: Research & Data
- Developer: beepboop2025
- Muse status: Extra setup. Not in Muse's Connectors list yet. Muse can still use it: its page gives you a request to paste into Muse.
- Health: Working, 220ms, checked 2026-09-28T08:16:11Z
- Endpoint: https://breach.seiche.info/mcp
- Auth: No account needed; Pricing: unknown
- Screening: Screened, no issues found (2026-09-25T05:31:33Z)
- Source: Found in the official MCP Registry (io.github.beepboop2025/data-breach-detector) https://registry.modelcontextprotocol.io/v0/servers?search=io.github.beepboop2025%2Fdata-breach-detector

Searches public breach disclosure feeds (HaveIBeenPwned, RansomLook, SEC filings) to report whether an organization was breached and what data types were exposed. Returns metadata only, never actual leaked data. Includes historical archive, threat assessment and trend analysis.

Example request: "Tell me if my company domain has ever appeared in a data breach and what information was exposed."

How to connect: Not in Muse's Connectors list yet, but Muse can still use it. Paste this into Muse: "Use Data Breach Detector to help me. It is a free service with an MCP server at https://breach.seiche.info/mcp. It does not need an API key. Ask me before you share anything with it." Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.

Tools:
- breach_news: Read recent breach and ransomware DISCLOSURES from public threat-intel feeds (HaveIBeenPwned, the RansomLook live leak-site tracker and SEC 8-K Item 1.05 filings), newest first. Every row is metadata only — entity, date, scale, exposed data TYPES, threat level and source — never 
- check_exposure: Answer whether a domain, company or brand appears in public breach or ransomware DISCLOSURES across ALL history (2007 → today): yes/no with mention count, worst threat level, total accounts exposed across matches, the exposed data TYPES, and the matching disclosure metadata — nev
- breach_history: Search the FULL historical breach archive — every incident this server knows about, back to 2007: HaveIBeenPwned's verified breach directory, the 2020-2025 ransomwatch leak-site archive (~16k victims), the RansomLook live tracker and SEC 8-K Item 1.05 filings. Filter by keyword, 
- breach_timeline: Build the incident-by-incident CHRONOLOGY of one organization across every source and all history, with judgment on top: first and latest incident, incidents per year, whether the organization is a repeat victim, worst threat level and total accounts ever exposed. Those summary f
- breach_stats: Aggregate the full breach archive into analyst-grade statistics: incidents and accounts exposed per year, per source, per exposed data type, per threat level, or per ransomware actor — plus the five largest incidents ever recorded. Use it to answer 'how has breach volume trended 
- assess_threat: Classify a piece of security text you supply — an advisory, alert or forum post — into a threat level, matched categories, financial-target flags, a confidence score and a recommended action. Pure local analysis: it collects nothing, stores nothing and reaches no network; the tex
- feed_sources: List the public disclosure feeds this server aggregates, how many disclosures are cached per source, each source's newest item and an honest staleness flag, plus cache ages. Takes no arguments. Also states the scope plainly: public feeds only — no .onion access, no arbitrary fetc

Screening checks:
- MCP handshake: pass (Answered in 427ms)
- Domain against threat feeds (Cloudflare security DNS): pass (breach.seiche.info not flagged)
- Published packages against the OSV malicious-package database: pass (No malicious-package advisories)
- Hidden instructions or invisible characters in tool text: pass (7 tools read, nothing found)
- Inputs asking for passwords, card numbers or seed phrases: pass (None found)
- Domain and redirects: pass (Domain registered 77 days ago)
- AI review of purpose and tool behavior: pass (No concerns)
