Daily data-breach news digest for your team's Slack

Every morning, get a plain-English roundup of the newest data breaches posted straight to your team's Slack channel, ranked by size and severity.

Agentic Task
Have I Been PwnedSlack BotOperationsEngineeringDaily DigestsResearch & Monitoring
PromptCreate

Every morning at 9am, run a plain-English data-breach news digest and post it to our team's Slack channel. This is a security-awareness digest about the wider breach landscape, not a scan of our own company's domain.

Pull the newest breaches from Have I Been Pwned. Use Get the Most Recent Breach to grab the single latest addition, and Get All Breached Sites to pull the full list of breached sites so nothing added recently is missed. Both operations are unauthenticated, but every request must send a descriptive User-Agent header, since a missing User-Agent is rejected.

Keep only breaches that were added in the last 24 hours. Each breach carries an AddedDate in ISO 8601 UTC. Use it to de-duplicate against older entries and to decide what is genuinely new since yesterday's run.

For each new breach, write a short plain-English summary covering three things: which site was hit, how many accounts were affected (the PwnCount), and which data classes were exposed. Translate technical labels into everyday language, for example turning 'password hashes' into 'scrambled passwords that attackers can try to crack', and keeping labels like email addresses, phone numbers, and IP addresses in plain words.

Rank the breaches by a combination of size (number of accounts affected) and sensitivity of the exposed data, most serious first. Clearly flag any breach that is unverified (not confirmed as genuine) or that came from a stealer log (logins harvested by malware on infected devices), so the team knows how much to trust each entry.

Post the finished digest to our team's Slack channel using Slack Bot's Send a Message. If nothing new was added in the last 24 hours, post a short 'no new breaches today' note instead, so the team knows the check ran.

Example output

🔒 Data breach digest: 3 new breaches in the last 24 hours 1. ExampleShop (12.4M accounts), verified. Exposed: email addresses, names, and scrambled (hashed) passwords. Large breach with crackable passwords, treat as high priority. 2. ForumX (900K accounts), unverified. Exposed: usernames, email addresses, and IP addresses. Not yet confirmed as genuine. 3. Stealer log capture (45K records), from malware. Exposed: website logins harvested from infected devices. Ranked by size and sensitivity. Source: Have I Been Pwned.

Additional information

What does this prompt do?
  • Every morning, checks Have I Been Pwned for data breaches added in the last 24 hours.
  • Summarizes each new breach in plain English: which site was hit, how many accounts were affected, and what kind of data leaked.
  • Ranks breaches by size and sensitivity, and flags any that are unverified or came from a stealer log.
  • Posts the digest to your team's Slack channel, or a quick 'no new breaches today' note when there is nothing new.
What do I need to use this?
  • A connection to Have I Been Pwned, the public database of reported data breaches.
  • A Slack workspace with the Slack bot added to the channel where you want the digest to land.
How can I customize it?
  • Change the time of day or how often the digest runs, for example twice a day or weekdays only.
  • Point it at a different Slack channel, or send it as a direct message instead.
  • Set a threshold for what counts as notable, such as only breaches above a certain size or only verified ones.

Frequently asked questions

Does this check my company's own email addresses?
No. This is a general news digest of newly reported breaches from across the internet, not a scan of your own domain. It keeps your team aware of what is happening in the wider breach landscape.
What happens on a day with no new breaches?
You get a short 'no new breaches today' note, so you know the check ran and nothing slipped through.
Do I need a paid Have I Been Pwned plan?
No. This digest reads the public list of reported breaches, which does not require a paid subscription.
What do 'unverified' and 'stealer log' mean in the digest?
Some breaches have not been confirmed as genuine, and some come from malware that harvested logins from infected devices. The digest flags both so your team knows how seriously to take each entry.
Can I send the digest somewhere other than Slack?
The digest posts to Slack by default, but you can change which channel or person receives it whenever you like.

Keep your team ahead of the next data breach.

Set up a daily breach digest and let your team read the headlines in Slack instead of hunting for them.