Breach Exposure

Checks daily whether your organization's email addresses turned up in third-party breaches, with severity and a clear recommendation.

Last reviewed:

Your team's credentials may be circulating today because of a breach that was not yours: the service that leaked was someone else's, but the reused password belongs to your people.

What it measures

Whether the corporate email addresses you specify appear in known breach databases — other people's leaks, from other services, that became public.

How to set it up

  1. 1

    Add the addresses to monitor

    One at a time, with the full corporate address. Start with the accounts that would do the most damage if compromised: leadership, finance, IT, and anyone with banking access.

  2. 2

    Wait for the first check

    It runs automatically within the next 24 hours. If you would rather not wait, *Check now* forces it — with a short pause between attempts.

  3. 3

    Let it run

    From then on the check is daily and needs nobody to log in and look. When a new match appears, an exposure is raised.

How to read the result

Each exposure carries the breach date, when we detected it, and — most importantly — what data was exposed. That last field is what sets the urgency:

Data exposedWhat it means
PasswordThe urgent one. If that person reused the password on any company system, there is a key in circulation.
Email address onlyLess severe, but not harmless: an attacker now knows that person exists and where they work. That is raw material for targeted phishing.

The summary highlights critical and high exposures that are unaddressed, which is the only figure needing action today. Each exposure also carries a plain-language explanation of what happened.

What to do with an exposure

  • If a password was exposed: force a change across company systems and confirm with that person that they are not reusing it elsewhere. The second part is what actually closes the gap.
  • If only the address was exposed: tell the person and put them on notice for targeted email. There is nothing to change, but there is someone to warn.
  • Mark it addressed once you have done what needed doing. It stops counting as pending and the history keeps the case.
  • Use the overlap with Passwords & Backups. If you also have that module, a password leaked here and a reused one there are the same person and the same problem.