This week
Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
The AI defense layer · Evidence-grade · Human-verified

Attackers have AI now. We read you first.

Attackers now point AI at every business from outside. Our agents read yours first, prove each way in, and close it before it is used.

Free. Use your work email at that domain. We send one confirmation link there, and your reading goes to that address only.

Read-only, from outside Proof for every finding Every assessment human-verified Continuous exposure watch
Reading · your-firm.comIllustrative
Ways in open
3
Each with its proof
Open: 3Closed: 0
Email sent in your nameDelivered
Discovernothing stops it
Addresses in breach databases3 found
Validatesource and date on each address
Website software1 open
Closeexact fix written, re-checked until closed
Look-alike domainsMonitored
Monitorre-read every hour
Illustrative firm · read-onlyHuman-verified
The AI era

Three ways AI is used against a firm today.

The message

Attackers use AI to write convincing fraud.

Fake invoices, cloned voices and emails that sound like your firm, tailored from what is public about you.

How it works

Your free reading shows whether email can be forged in your name.

How firms are hit today
The research

Attackers use AI to research your firm.

It reads your website and staff pages to learn who approves payments and who your suppliers are.

Organised fraud groups also run AI built without safety limits.

The wrong door

Your clients’ AI assistants can give out a number or login that is not yours.

A wrong answer sends your client to whoever answers.

How it works

The AI Impersonation Check comes with the assessment: it asks those assistants about your firm, traces each wrong answer to its source and prepares the correction.

When AI sends your client to the wrong number

Your free reading shows what an attacker can see from outside. The assessment adds the AI Impersonation Check.

Business email compromise (BEC)
$3,046,598,558

Reported losses to business email compromise in the United States in one year: a scam that uses a hijacked or imitated business email account to get a payment sent. 24,768 complaints, 2025.

Source: FBI IC3 2025 Internet Crime Report, 2025. Reported losses only.

Check my firm

There’s only one answer to AI-powered attacks: AI-powered defense.

See one finding

One finding, read from outside, proven, human-verified and closed.

Captions available, no sound. Illustrative firm.

Read the transcript
  1. There's only one answer to AI-powered attacks. AI-powered defense.
  2. A score-only rating: 62/100, Grade C. No record behind it. Nothing to re-run.
  3. What we hand you: the firm’s public email record tells other mail servers to take no action on forged mail. Read 5 Oct 2026. Human-verified.
  4. Proof, not scores. Dated and checkable by anyone, your insurer included.
  5. One setting changes. Forged mail in the firm’s name is then refused. Re-checked from outside.
  6. You get the fix for each finding, step by step, and we re-check until it is closed.
  7. Every paid assessment is human-verified before release.
  8. On monitoring: re-checked every hour, 24/7.
  9. The AI defense layer for the world’s businesses. Proof, not scores. Check my firm · getleaktrace.com
The good news

Anything an attacker can see from outside, we can find and close first.

Attacks on firms like yours still start with something anyone on the internet can see: an email setting that lets forged mail through, a staff password in a breach database, a look-alike domain, an open sign-in page. Each of those can be found from outside before an attacker uses it.

24/7 Monitored day and nightRe-checked every hour on monitoring
1 h First to knowAlerts within the hour on hourly checks
The difference

Every finding, proven.

Every finding we show carries the record behind it and a check anyone can re-run, your insurer included. Human-verified before it reaches you.

Counted from our own records as of 8 Oct 2026, 21:03 UTC, refreshed hourly. Illustrative items are labelled.
213.5K

Look-alike domains checked

Brand impersonation caught within the hour it goes live, on monitoring.

185.7K

Certificate records read

New host names on your domain found as they are certificated, re-checked hourly on monitoring.

2,590

Firms read from outside

Each read the way an attacker’s tools read it, from public sources, logged into nothing.

Show moreShow less
1 clickTo protect your name against forged email, where we can reach your DNS host
Newest on the exploited list
Citrix NetScalerAdded 4 Oct · Citrix NetScaler Improper Restriction o…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Session Fixation Vul…
Zammad GmbH ZammadAdded 2 Oct · Zammad GmbH Zammad Improper Privilege M…
1 dayTo match a newly exploited flaw to the software a monitored firm’s site shows
5,263Public disclosures indexed, each with the way in. Updated daily
2,587Firms whose addresses were checked against monitored breach databases
72 hFrom confirmation to a human-verified assessment
Public sources only
Your websiteOpen to anyone
Your email setupOpen to anyone
Public recordsOpen to anyone
Breach listingsOpen to anyone
0Log-ins to any client system. Every check is a public lookup, like this one.

Check my firm

How the AI defense layer works

Every way into your firm, found first, proven and closed.

Agent against agent: attackers point AI at firms, and our agents read yours first. Continuous exposure watch, AI-driven and read from outside, in four stages: Discover, Validate, Close and Monitor. The next machine-speed attack finds the door already shut.

4 steps · click each
1 Discover1 Discover

Discover every way in

Every way into your firm, discovered from outside the way an attacker’s tools read it. Nothing to install, no access to give.

The Discover agent reads what your firm shows the public internet and records each finding with its evidence.

6Exposure classes watched, from forged email to AI impersonation
HourlyEmail settings, look-alikes and new host names re-checked, on monitoring
What we monitor
Email impersonationEvery gap in the records that say who may send email as your firm, found and closed
Brand impersonationLook-alike domains caught within the hour they go live, and, if it is not yours, a takedown request drafted
Attack surface discoveryEvery new system exposed on your domain, found as it appears
Exploited vulnerabilitiesFlaws attackers are actively using, matched to your website’s software within a day
Credential exposureYour firm’s addresses in breach data, flagged before the passwords are reused
AI impersonationNumbers and login pages that are not yours, handed to your clients by AI assistants, each traced to its source, with the correction
2 Validate2 Validate

Validate every finding

The exact record behind each finding, a check anyone can re-run, and human verification before release. Every paid assessment carries a signed record anyone you hand it to can verify in one step.

Every finding is kept with the record that proves it. A person reads the assessment before release.

EveryPaid assessment is checked by a person before release
72 hFrom confirmation to an approved assessment
Verify a record
Evidence for every findingThe exact record, header or listing behind it
Signed assessment recordDated, and verifiable by anyone you hand it to
Tamper-evident recordEvery approval, alert and DNS change hash-chained and verified daily
Anti-impersonation checkAnyone can confirm in one step that a message really came from us
3 Close3 Close

Close each opening

Forged email, the opening we find most, closes in one click where we reach your DNS host: staged, re-checked, nothing changed until you confirm. You get the fix for the rest, step by step, and we re-check until it is closed.

The Close agent gives you the fix for each finding and re-checks from outside when you mark one done.

1 clickProtects your firm against forged email in its name, where we reach your DNS host
Pre-filledThe outside questions on your cyber application
How it works
One-click email fixWhere we can reach your DNS host; the exact records where we cannot
Takedown request draftedFor a look-alike worth a look that you say is not yours, for you to send
Patch before it is usedNewly exploited flaws matched to your software, with the fix
Insurance questions pre-filledThe outside questions on your cyber application, with the evidence
4 Monitor4 Monitor

Monitor around the clock

Re-checked every hour, 24/7, with alerts within the hour. You are first to know, before a client, a bank or an insurer.

On monitoring, the Monitor agent re-checks your email settings, look-alike domains and new host names every hour, and everything else every day.

1 hAlerts within the hour on hourly checks, by email, Slack or Teams
24/7Monitored day and night; the same day for daily checks
For firms
Alerts within the hourThe way in, in plain words, within the hour on hourly checks and the same day on daily ones
Slack or TeamsAlerts where your partners already talk, or by email
Board-ready summaryBoard-ready exposure summary, every month
Peer benchmarkYour exposure ranked against firms in your sector, where 30 or more are measured
The ways in that matter most

How firms are hit today, and our answer to each.

We can check three of these seven completely from outside, and three partly. The last one needs someone to look inside your systems, and we tell you that plainly.

The way inOur figureWhat we doCoverage
Email forged in your nameFake invoices and changed bank details, sent as you.
3 in 4professional firms cannot stop a stranger sending email in their name.LeakTrace index, readings to 8 October 2026
  • Discover: the setting that lets forged mail through.
  • Validate: with the public record behind it, dated and checkable by anyone.
  • Close: in one click where we reach your DNS host; the exact record where we cannot.
  • Monitor: re-checked every hour.
CoveredFrom outside, end to end.
Stolen or reused passwordsA firm address in a breach database, and a password used again.
2 in 10professional firms have a shared address such as info@ in monitored breach databases.LeakTrace Research · Measured 30 Sep 2026
  • Discover: which firm addresses appear, with the source and date of each.
  • Monitor: re-checked every day.
Covered
Look-alike domains used to impersonate youA domain made from your firm’s name, set up for email, with no website.
4 in 10professional firms have a look-alike of their domain registered and live.LeakTrace Research · Measured 30 Sep 2026
  • Discover: registered domains made from your name, each one we raise with its public record.
  • Validate: only what we observed, and one question: is it yours?
  • Close: a takedown request drafted, ready for you to send.
  • Monitor: re-checked every hour for new ones.
Covered
Known flaws attackers are exploiting nowNewly listed flaws in the software a website runs.
1,734Actively exploited flaws we watch forCounted from our own records
  • Discover: matched to the software your website shows, within a day of being listed.
  • Monitor: every new listing, every day.
PartlyYour website only.
Exposed sign-in pages and remote accessPortals, admin pages and remote-access ports anyone can reach.
  • Discover: which sign-in pages answer from outside, and which remote-access ports are open on your website’s host.
PartlyWe cannot see from outside whether multi-factor sign-in is switched on. Your IT provider can, and we tell you to ask them.
AI-written phishing and impersonationEmails that AI tailors to the person who receives them.
  • Close: email forged in your name, as above.
  • Validate: in the assessment, what AI assistants tell clients about your phone number and client login, checked against your own site; each wrong answer traced to its source, with the correction.
PartlyA convincing email sent from some other address goes straight to your people, and no setting of yours can block it. We tell you that plainly.
RansomwareIt usually gets in through one of the openings above.
  • Close: those outside openings, one by one.
Not visible from outsideWe cannot see your backups or internal systems from outside, and we tell you so.

Figures are LeakTrace Research, measured across the firms we have assessed, each with its date. Everything here is read from outside, from public sources only.

The latest · 8 Oct 2026

How they got in this week, and what we watch for you.

United StatesPublic source8 Oct 2026The Hacker News

US critical infrastructure

How they got in
A known flaw in software the victim ran.
What we watch
Software versions your site advertises and known flaws in them.
RussiaPublic source8 Oct 2026SecurityWeek

Organizations using Fortinet devices

How they got in
Stolen or reused passwords.
What we watch
Your firm's addresses in monitored breach databases.
South KoreaPublic source8 Oct 2026Infosecurity Magazine

South Korean financial firms

How they got in
A known flaw in software the victim ran.
What we watch
Software versions your site advertises and known flaws in them.
LeakTrace Research

What anyone can see about professional businesses, measured.

See the research
  1. Nearly9 in 10

    dental practices cannot stop a stranger sending email in their name.

    LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records
Show allShow less
  1. Nearly9 in 10

    dental practices cannot stop a stranger sending email in their name.

    LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records
  2. Nearly5 in 10

    accounting firms have a look-alike of their domain registered and live.

    LeakTrace Research · measured 30 Sep 2026 · 46.4%, common misspellings checked in public DNS
  3. 3 in 10

    accounting firms have a shared address such as info@ in monitored breach databases.

    LeakTrace Research · measured 30 Sep 2026 · 28.9%, shared addresses checked in monitored breach databases
The rules you answer to

Every finding, mapped to the rule you answer to.

A pen test covers what it is scoped to, once. Every assessment runs up to 37 outside checks, with email settings, look-alikes and new host names re-checked every hour on monitoring. We hand you the record your regulator, your insurer and your partners ask for.

FindingEmail forged in your name
The rule it touchesABA Model Rule 1.6 and FTC Act Section 5The duty to protect client information; your state bar adopts its own version.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
Show allShow less

Law

FindingEmail forged in your name
The rule it touchesABA Model Rule 1.6 and FTC Act Section 5The duty to protect client information; your state bar adopts its own version.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingFirm addresses in breach databases
The rule it touchesABA Model Rule 1.6 and state breach notification lawsNotice when personal information is exposed; timing varies by state.
What we hand youThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Does your domain enforce DMARC at quarantine or reject?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Accounting

FindingFirm addresses in breach databases
The rule it touchesFTC Safeguards Rule, 16 CFR 314.4Multi-factor sign-in for anyone accessing customer information.
What we hand youThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingEmail forged in your name
The rule it touchesFTC Safeguards Rule, 16 CFR 314.4A security program that safeguards customer information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingInsurer asks: Are staff email addresses clear of known breach data?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Medical

FindingEmail forged in your name
The rule it touchesHIPAA Security Rule, 45 CFR 164.308Administrative safeguards for patient health information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingStaff addresses in breach databases
The rule it touchesHIPAA, 45 CFR 164.404Tell patients of a breach within 60 days of discovery.
What we hand youThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Do you require multi-factor sign-in for email and remote access?
The rule it touchesYour cyber insurance applicationWe cannot see this from outside, and we tell you so.
What we hand youWhat we did see that bears on it, so the answer you give is your own.

Wealth

FindingEmail forged in your name
The rule it touchesRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmWritten policies and procedures to safeguard customer records and information, including an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
What we hand youThe dated record, the fix (one click where we reach your DNS host) and the outside re-check that proves it closed.
FindingA look-alike of your domain, registered and live
The rule it touchesRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmAn incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
What we hand youEach one named; if it is not yours, a takedown request drafted with the evidence.
FindingInsurer asks: Do you keep internet-facing software patched and up to date?
The rule it touchesYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
What we hand youWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Shown for the United States. Only the rules the Rules and Insurance Briefing maps; which one applies depends on your business, and your briefing names it.

All rules we map
FTC Act Section 5US

Safeguard consumer data. Failures are treated as unfair or deceptive practices.

SEC Regulation S-PUS

SEC-registered advisers and broker-dealers: an incident response program, oversight of service providers, and notice to affected customers no later than 30 days after becoming aware.

FTC Safeguards RuleUS

Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.

HIPAAUS

Covered clinics: protect patient health information and tell patients within 60 days of discovery.

State breach notification lawsUS

Notify affected people when personal information is exposed. Timing varies by state.

201 CMR 17.03US

Anyone holding a Massachusetts resident's data: review the written security program every year.

PIPEDACA

Safeguards appropriate to the sensitivity of the information. Notify of a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.

Alberta PIPACA

Prompt notice to the Commissioner where harm is a real risk.

BC PIPACA

Reasonable security arrangements against unauthorized access.

PHIPACA

Ontario health custodians: protect patient information and notify the Information and Privacy Commissioner of breaches.

The rules for your country come first. We list a rule only where we can say honestly whether it applies to you.

Who it is for

For the firms that hold other people’s money and confidences.

Show allShow less
Independence

Outside only. Independent, and answerable to you.

We read what your firm shows to the public internet, and nothing else. What we find goes to you alone.

Your IT provider keeps your systems running. We read your firm from outside, independently, and show you what is open, each finding with its evidence.

A penetration test needs access to try to break in. We read only what is already public, and log into nothing.

Your insurer’s scan can feed your premium, and we do not see it. We show you what anyone can see of your firm from outside first, so you walk into renewal knowing your own answers.

Access neededNone
Log-ins to your systemsNone
Mutual NDAAvailable on request
Questions
Nothing of yours. We read what your firm shows to the public internet, the way an attacker’s tools would. Our agents work from outside only. They never log in, never install anything, and never touch your internal systems. The one change they can make, to your email records, happens only when you approve it.

See your firm the way an attacker’s AI sees it.

Your outside reading: your email setup, your website, look-alike domains, staff passwords in breach databases and your sign-in pages, each with its evidence; the fix steps, the AI Impersonation Check and an AI security agent on your dashboard come with the assessment. Free, read-only, and sent only to your work email.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request

A person reads every request. We reply within one business day from [email protected]. Privacy

The incidents that reach firms like yours, and what to check, in one email. Sign up