In short: Researchers at Open Measures documented a cluster of AI tools, built by users of the imageboard Soyjak Party, that automate doxing — assembling a dossier on a person from a single name or email. They wire a language model into third-party breach databases and search interfaces to pull emails, accounts, IP addresses and geolocation in minutes. The tools are crude and error-prone, but they lower the skill barrier for mass harassment. Here is what it means for your data and how to shrink your exposure.
What happened
Open Measures, which studies online extremism, found discussions of at least three such services on Soyjak Party, appearing from October 2025 onward. The developers did not train their own model — they connected existing large language models to leak databases and public search tools, then wrapped them in a simple interface. A user types a name, and the system returns email addresses, accounts, IP addresses, geolocation and other identifiers. One early tool supported batch searching, source filtering and location lookup by IP address.
On 6 March 2026 a user on the site's /raid/ board debuted what they called a "fully autonomous, free doxxing AI agent" — a system prompt casting the model as a "professional private investigator" that, its author claimed, produced a complete profile of a target in a single prompt. This is the same aggregation problem we described in our report on how scattered traces are stitched into a profile: the danger is not one secret file, but many ordinary fragments combined.
How the tools work — and why they are unreliable
Because these agents pull from breach databases, they are only as good as the leaked data behind them. Open Measures found ready-made reports on at least four private individuals, plus mentions of the tools on the Kiwi Farms forum and on Discord. But users of the board themselves flagged a serious flaw: the language models hallucinate. They mix up data belonging to different people or invent details outright, so a generated "dossier" can confidently name the wrong person. That does not make the tools harmless — it makes them dangerous in a different way, since a plausible but false profile can still trigger harassment of an innocent person.
Where the data comes from
None of this works without raw material, and the raw material is leaks. Every breach that spills emails, phone numbers and passwords onto the market becomes fuel for exactly this kind of automated profiling. We have tracked how large those dumps get in our piece on the billions of credentials exposed by infostealers. The IP-and-geolocation angle matters most for everyday readers: your IP address is a routine part of your online footprint, and tools like these use it to guess where you are.
What it means for an ordinary person
You do not have to be a public figure to be doxed. As the skill barrier drops, targets are chosen on a whim — an argument in a game, a comment in a chat. The building blocks of a dossier are the traces you already leave: an email reused across sites, a phone number tied to old accounts, an IP address that reveals your city. The less of that is exposed and linkable, the harder it is for an automated tool to stitch a convincing profile of you.
How do you protect your data?
Shrink what is linkable. Use separate emails for sign-ups, unique passwords with a manager, and two-factor authentication so one leaked login does not unlock the rest of your identity.
Check whether you are already in a breach. If your email appears in known dumps, change those passwords first — that is the data these tools feed on.
Hide your IP on untrusted networks. IP-based geolocation is a core input for these tools. A no-logs VPN replaces your real IP with the address of a VPN server, so an IP lookup points to the server, not your home, and the network you are on cannot log which sites you visit. An honest limit: a VPN does not erase data that has already leaked, and it will not stop someone who already knows your real name from searching public records — it reduces one signal, IP and traffic exposure, not all of them. LiMP VPN is a no-logs service for iOS and Android — see the plans, and follow more privacy news on our blog.
Sources
This report is based on the investigation by Open Measures and reporting by SecurityLab.ru, which independently described the AI doxing tools.
