What it had to solve
Existing notification services had two problems, per Julian: most users didn't know they existed, and many distrusted handing their credentials to yet another online service.
How it works
Over three days Julian collected leaked email/password combinations from PasteBin-style sites; on May 19, 2015 his tool Canary sent 97,931 pre-written warning emails; by late June he had collected 300,000 login credentials and was weighing another blast.
What it did
Nine thank-you replies and zero donations — 'since the campaign didn't cost me much, it's also absolutely fine'; Julian called the experiment a success, hoping many helped never replied because they lost the email to spam filters.
Background
Every major hack dumps email and password combinations onto the black market, and Slate's Lily Hay Newman noted the obvious: most of us never check whether our credentials are among them. 'Julian', the pseudonymous blogger behind ATechDad, decided to check for us. Over three days he collected leaked user data posted to plain-text hosts like PasteBin, using a scraper he built called Canary, which automatically culled select data from web pages and sent pre-written emails alerting people their credentials were exposed.
The design insight was trust. Similar scraping services already existed, Julian wrote, but '1. Most users have no idea these services exist. 2. Many users are wary of sending the information they care most about to another online service.' His answer: the credentials could speak for themselves — if they're on PasteBin, the owner should be notified, no sign-up required.
On May 19, 2015, Canary emailed 97,931 people whose cybersecurity was at risk. Motherboard pointed out many would ignore an email that looked like phishing; Julian got nine thank-yous, no donations ('this was not unexpected'), and by late June had collected 300,000 login credentials, contemplating a second blast. 'Overall I consider this experiment a success,' he wrote.
Why it lands
Removing the sign-up step removed the trust barrier: victims learned of the leak without ever handing data to a stranger.
The whole apparatus was one scraper and pre-written emails — a one-person public service at near-zero cost.
The lukewarm response rate itself was the finding: breach notification by cold email barely works, which is the problem services still haven't solved.
What you can take
The notification gap is a design problem: meet people where the leak already surfaced, instead of asking them to trust yet another service.
Since then
As of late June 2015, Julian had 300,000 collected credentials, nine thank-yous, and a decision to make about a second email blast — with the experiment documented publicly on ATechDad and covered by Slate and Motherboard.
FOLLOW THE EVIDENCE