/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Pastebin, a popular destination for hackers, quietly removed a scraping API, frustrating researchers and making it harder to search for data breaches and more

Lorenzo Franceschi-Bicchierai / VICE :

VICE Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

For years Pastebin has been one of the places hackers dump stolen credentials and breach data, and its scraping API was how security researchers kept automated watch over those dumps. The quiet removal lands on an ecosystem that has already been losing its public archives: LeakedSource, which sold access to a database of over 3.1 billion compromised passwords, was taken offline after an alleged police raid in early 2017, and Leakbase, which indexed passwords from major breaches, shut down months later with sources tying its closure to the Hansa dark web market raid.

That history matters because each closure pushed breach monitoring further into informal channels — and Pastebin's API was one of the last open, programmatic windows onto where fresh dumps actually appear. Reporter Lorenzo Franceschi-Bicchierai's sourcing here centers the people who lose most from that window closing: the independent researchers who police leaks without institutional budgets.

First-order effects

  • Security researchers who used the scraping API to programmatically search Pastebin for breach dumps and malware samples lose their main automation path and fall back to slow manual searches.
  • Pastebin itself trades researcher goodwill for reduced exposure: bulk scraping made its contents easy to mirror and analyze, including by parties the site might prefer not to serve.

Second-order effects

  • With LeakedSource raided offline and Leakbase shut down, the removal leaves no obvious centralized index of breach data, pushing monitoring costs onto individual researchers and commercial threat-intelligence vendors who must rebuild collection from scratch.
  • Dumpers gain relative cover: if fewer researchers can sweep Pastebin systematically, credential lists posted there circulate longer before being flagged or remediated by affected companies.

Third-order effects

  • If the pattern holds — public archives shuttered or locked behind raids, APIs withdrawn — breach research structurally migrates toward paid threat-intel platforms and private sharing circles, thinning the independent-researcher layer that currently surfaces leaks like exposed credentials in public pastes.
  • Paste sites face a widening legitimacy gap: closing researcher access while remaining a hacker destination invites the same law-enforcement attention that ended LeakedSource and Leakbase, pressuring the category toward either moderation or eventual takedown.

The trend: Open infrastructure for tracking leaked data keeps contracting — raids took the commercial indexes, and now paste-site APIs are withdrawing — leaving breach monitoring to consolidate inside paid threat-intelligence and private researcher networks.

Discussion

  • @ildannymoore Daniel Moore on x
    It was always suspicious that Pastebin had no search API, clearly to hide the extent of abuse in it's platform for which they have no solution. This latest move to disable their scraping API will hurt security research more than anything else. https://twitter.com/...
  • @vice @vice on x
    Pastebin quietly changed its terms and services that allowed researchers to study leaked data, malware, and stolen passwords. https://www.vice.com/...
  • @jason_koebler Jason Koebler on x
    pastebin is up to some extremely shady shit right now: https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    Pastebin is used by hackers to dump all sorts of information that researchers then try to spot and warn victims of. But Pastebin has closed its API and even its basic search function making that much harder https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Pastebin didn't really answer any questions and just pointed to its terms and conditions. This won't stop hackers using Pastebin to distribute content; only people trying to research them https://www.vice.com/... https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    New: Pastebin quietly turned off search and an API to scrape the site, making it harder to find data breaches, leaked passwords, and malware payloads. Secrutiy researchers are pissed, and the company's response has essentially been: “deal with it.” https://www.vice.com/...