Why We Will Not Run a Breach-Database Lookup, and It Is Not Squeamishness

2026-09-02 · Philip Choo · AI9OS

A generated query pack for an asset-tracing matter came back with thirty-four templates in it. Three of them hunted leaked credentials against a person who was not our client and had consented to nothing. They sat in the same undifferentiated run list as the company searches and the land registry queries, with nothing beside them to say they were different. Whoever ran that pack that morning would have had to notice, unprompted, that three of the thirty-four were a criminal exposure.

That is the defect. Not the three templates. The fact that catching them was left to a person's memory on a busy morning.

The legal line is the easy part

In Singapore the point is settled and short. The Computer Misuse Act 1993 s 8A makes dealing in personal information obtained through a CMA offence an offence in itself. A credentials dump circulating on a forum is data obtained through unauthorised access, and buying it, holding it or searching it does not become lawful because it is already in public circulation. "Anyone can download it" is not the statutory test. We have set this out before in the Singapore OSINT legal checklist and in the note on lawful bases under the PDPA, and the position has not moved.

So the first answer to a client asking for a breach lookup is that it is against the law. That answer is true and it is also the least interesting reason, because it is the one every competent practitioner already knows and it still does not stop the query being run.

The finding is unexhibitable, so the risk buys nothing

Here is the part that gets missed. Suppose the lookup works. Suppose it returns the subject's password reuse across three services and confirms an alias.

You cannot use it.

You cannot put it in a report that goes to counsel. You cannot exhibit it. You cannot describe its provenance without describing the offence, and provenance is the whole basis on which a finding survives contact with the other side. A finding whose origin cannot be stated is not a weak finding; it is not a finding at all, and it contaminates the sound work sitting next to it, because opposing counsel who find one unexhibitable item will go looking for a second.

So the trade is a criminal exposure in exchange for something you can never produce. That is not a fine judgement about risk appetite. It is a bad deal at any price. Where a lawful route to the same fact exists, take it and pay for it. Where it does not, the honest output is that the fact is not established, which is a legitimate result and one we write down as a status rather than a hedge.

A red line that depends on memory is not a red line

Now the argument this post exists for.

Every firm has this rule written down somewhere. Ours was written down. It was in the jurisdiction checklist, in the onboarding material, in the client-facing scope language. And it still produced a run list with three prohibited queries in it, because a rule that lives in a document and a rule that lives in the tool are not the same rule.

The tool is where the decision actually gets made. At the moment of use, the operator sees a list. If the list presents a prohibited query in the same typeface, the same section and the same ordering as a company search, then the control being relied on is the operator remembering, under time pressure, something they read during onboarding. That is not a control. It is a hope with a policy document attached.

The test is simple and it is worth applying to every red line a firm claims to have: if the person having a bad day does the obvious thing, what happens? If the answer is "an offence", the control is in the wrong place. Move it.

What moving it looks like

Four changes, and none of them is difficult.

  • Flag the offending templates in the library itself, at source, so the classification travels with the template rather than being reapplied by whoever reads the output.
  • Emit them into a separate EXCLUDED section, not the run list. The operator should have to leave the workflow to reach them, not stay in it.
  • Print the governing statute beside each one. Not "prohibited". The section number. A person who can see Computer Misuse Act 1993 s 8A next to a query does not need to recall a training slide, and a person who wants to argue for an exception now has to argue against a citation.
  • Enforce at generation, not at the operator's discretion. If the pack is built correctly, the wrong query is never presented as an option in the first place.

The fourth is the one that matters. The first three make the red line visible. Only the fourth makes it structural.

Key the flag to the jurisdiction, not to a global switch

One refinement, because a global prohibition is its own kind of sloppiness.

Whether a given template is lawful varies by jurisdiction, and a firm working across several will get this wrong in both directions if it flips a single switch. Flag globally and you will block work that is lawful where it is being done, which trains people to override the flag. Train people to override a flag once and the flag is finished. Flag nowhere and you are back to memory.

So the flag keys to the jurisdiction file. The same template is excluded in one matter and permitted in another, for a stated reason, with the governing provision printed either way. That also means the control gets updated when the law does, in one place, rather than in the recollection of everyone who has ever run the pack.

What to say when a client asks for it

They will ask, and usually not because they are trying to get anyone into trouble. They have read that this data exists and they cannot see why a firm with the tooling would not look.

The answer is two sentences and it should not be apologetic.

We do not search breach or credential data, because obtaining or dealing in it is an offence under the Computer Misuse Act and anything found that way could not be exhibited. Here is the lawful route to the same question, and what it costs.

The second half is what makes the first half land. A refusal on its own reads as fastidiousness. A refusal with the lawful alternative priced beside it reads as competence, and it is the same instinct behind declining work we cannot actually deliver: the client is not buying our willingness, they are buying a result that holds up.

The general form

There is a pattern here that outlives this particular query.

Any rule your firm considers non-negotiable should be findable in the thing people touch, not only in the thing people were shown once. Ask where each of your red lines is actually enforced. If the honest answer is "the operator knows", then what you have is a preference. It will hold for years and then fail on the one morning that matters, and it will fail silently, because nothing in the workflow was ever built to notice.

We found ours in a pack of thirty-four. The uncomfortable part was never the three templates. It was that the tool had been offering them for as long as the tool had existed, and the rule had been holding purely because nobody had yet been busy enough to miss them.

AI9OS turns public information into verified, chain-of-custody findings for licensed investigation agencies, law firms and corporate risk teams.

Request a demo