Breach Exposure
Checks daily whether your organization's email addresses turned up in third-party breaches, with severity and a clear recommendation.
Last reviewed:
Your team's credentials may be circulating today because of a breach that was not yours: the service that leaked was someone else's, but the reused password belongs to your people.
What it measures
Whether the corporate email addresses you specify appear in known breach databases — other people's leaks, from other services, that became public.
How to set it up
- 1
Add the addresses to monitor
One at a time, with the full corporate address. Start with the accounts that would do the most damage if compromised: leadership, finance, IT, and anyone with banking access.
- 2
Wait for the first check
It runs automatically within the next 24 hours. If you would rather not wait, *Check now* forces it — with a short pause between attempts.
- 3
Let it run
From then on the check is daily and needs nobody to log in and look. When a new match appears, an exposure is raised.
How to read the result
Each exposure carries the breach date, when we detected it, and — most importantly — what data was exposed. That last field is what sets the urgency:
| Data exposed | What it means |
|---|---|
| Password | The urgent one. If that person reused the password on any company system, there is a key in circulation. |
| Email address only | Less severe, but not harmless: an attacker now knows that person exists and where they work. That is raw material for targeted phishing. |
The summary highlights critical and high exposures that are unaddressed, which is the only figure needing action today. Each exposure also carries a plain-language explanation of what happened.
What to do with an exposure
- If a password was exposed: force a change across company systems and confirm with that person that they are not reusing it elsewhere. The second part is what actually closes the gap.
- If only the address was exposed: tell the person and put them on notice for targeted email. There is nothing to change, but there is someone to warn.
- Mark it addressed once you have done what needed doing. It stops counting as pending and the history keeps the case.
- Use the overlap with Passwords & Backups. If you also have that module, a password leaked here and a reused one there are the same person and the same problem.