Oracle PeopleSoft Campaign · 3M records · Ongoing· NYC Health Hospitals · 1.8M records · Ongoing· MCBS · 1.2M records · unknown· Essex NHS Trust · 900K records · unknown 2024· Tribeca Film Festival · 666K records · Unknown 2026· CommonSpirit Health · 19K records · Unknown 2026· Dutch retailer De Bijenkorf · Aug 2026· Apache Tomcat · Aug 2026· The top cybersecurity product · Aug 2026· Swiss federal IT office · Aug 2026· Oracle PeopleSoft Campaign · 3M records · Ongoing· NYC Health Hospitals · 1.8M records · Ongoing· MCBS · 1.2M records · unknown· Essex NHS Trust · 900K records · unknown 2024· Tribeca Film Festival · 666K records · Unknown 2026· CommonSpirit Health · 19K records · Unknown 2026· Dutch retailer De Bijenkorf · Aug 2026· Apache Tomcat · Aug 2026· The top cybersecurity product · Aug 2026· Swiss federal IT office · Aug 2026·
2026 breach index. Ranked by scale, updated as incidents are disclosed

Institutional
cyber intelligence.

The same rigor Kroll and K2 charge Fortune 500 executives six figures for. Family offices, wealth firms, sports agencies, and boutique counsel. Delivered inside a week, not eight. Mutual NDA before we go concrete.

Mutual NDA required
72-hour delivery
Encrypted
For business →
Why Now

Cybercriminals move at AI speed. Your monitoring should too.

Cybercriminals now use AI too. Phishing emails generate in bulk. Deepfake impersonation targets executives, athletes, family principals, and their households. Stolen breach data gets scraped and indexed within hours of a leak. Target lists build themselves.

Live counter
Business Email Compromise · reported losses, year to date
$0
Business Email Compromise: an attacker gets inside an inbox, watches finance traffic, then redirects a wire to themselves. Highest-loss internet-crime category the FBI tracks, ten years running.
$3.04B
2025 full year (FBI IC3)
$10B+
Estimated true global losses
$123K
Average loss per incident
Counter ticks live from Jan 1 at the FBI's reported run rate · Sources: FBI IC3, Microsoft Digital Defense, APWG eCrime (2025)

Shadow · read-only forensic audit of every inbox in your domain, ranked by wire-fraud risk. See how it works →

Live Threat Intelligence
287,869 Active Incidents Open Full Map
How It Works

The LeakTrace Methodology.

01
Domain Fingerprinting

Full enumeration of your external attack surface · DNS, certificates, exposed services, and infrastructure identifiers attackers see first.

02
Source Correlation

Multi-source correlation across the same intelligence layers attacker tooling operates on. Criminal marketplaces, breach repositories, and paste archives · continuously indexed.

03
Risk Quantification

Proprietary risk model surfaces a composite exposure score (0–100) with severity classification. Continuously calibrated against emerging threat patterns.

04
Intelligence Delivery

Analyst-grade briefing suite · executive summary, technical evidence, statutory mapping, prioritized remediation roadmap. Delivered under 24 hours.

05
Continuous Surveillance

Automated daily rescans. Threshold-based alerting on new exposures. Longitudinal risk trend analysis.

The Intelligence Layer

Criminals already
have this data.

Compromised credentials, infrastructure metadata, and Business Numbers persist across breach repositories, paste archives, and data broker networks. This information has been queryable since the moment the data was stolen.

LeakTrace correlates those same sources. The difference between visibility and exposure is whether the data is mapped before an attacker uses it.

Records are indexed at population scale. Your profile is already assembled in the databases attacker tooling references.
Credential Repositories

Major breach databases containing billions of compromised credentials, cross-referenced by domain, email pattern, and organizational association.

Data Broker Indices

Business Numbers, contact records, and organizational metadata aggregated across commercial data broker networks and public registry filings.

Threat Intelligence Feeds

Paste site archives, credential-leak archives, and active monitoring channels where stolen data surfaces and is distributed.

Infrastructure Signals

DNS layout, certificate chains, open service listing, header analysis. Automated scouting identifies the same gaps that attacker tooling maps.

Exposure Landscape
1 in 3

Individuals With Documented Credential Exposure

The median individual appears in four or more confirmed breach events. The data is indexed, searchable, and actively referenced by attacker infrastructure.

$16.6B
Internet crime losses recorded in 2024
FBI IC3, 2024
$4.44M
Average cost of a single business breach
IBM, 2024
194
Days the average organization takes to discover they were breached
IBM, 2024

194 days. The average time between initial compromise and detection. During that window, the organization operates without visibility into an active attacker inside its systems.

LeakTrace correlates the same intelligence sources used in attacker scouting. Exposure is identified and quantified before an attacker can act on it.

Internet Crime Losses. USD FBI IC3 Data
$16.6B ▲ 33% YoY
Projected →
2019202020212022202320242025
$16.6B in 2024
Reported losses only. True cost estimated 3–5× higher. Source: FBI IC3 Annual Report.
Latest Briefing
Insurance brokers · Aug 5, 2026 · 8 min

The Cyber Application Question Your Client Cannot Actually Answer

Cyber insurance applications ask questions small businesses check 'yes' on because they think they should. When the claim arrives and the answers get audited, the carrier denies. The broker who wrote the policy is the next defendant.

How We Engage

Four ways we work.

From a personal identity check to executive protection to full business threat monitoring. Every scan runs the same forensic analysis and gets a senior-analyst review.

Methodology Anchored In

Research methodology mapped to the frameworks your compliance file already cites.

United States · Federal
SEC Reg S-P
Advisor confidentiality
GLBA
Financial safeguards
FINRA
Examination-ready
FTC Safeguards
16 CFR 314
NIST CSF 2.0
Evidence handling
HIPAA
Health-adjacent scope
FBI IC3
Wire fraud + BEC
United States · State
CCPA / CPRA
California privacy
Canada
PIPEDA
Canadian privacy
CIRO
Canadian advisor
Attestation & Counsel
SOC 2
Audit in progress
ABA Rule 1.6
Counsel confidentiality