This week
Attacker’s-eye view · Evidence-grade · Human-verified

The AI defense layer.

Attackers use AI to find a way in. LeakTrace finds it first and closes it.

Free. Use your work email at that domain. We send one confirmation link there, and your reading goes to that address only.

Read-only, from outside Evidence for every finding Every assessment human-verified Continuous exposure watch
Reading · your-firm.comIllustrative
Ways in open
3
Each with its evidence
Open: 3Closed: 0
Email sent in your nameDelivered
Discovernothing stops it
Addresses in breach databases3 found
Validatesource and date on each address
Website software1 open
Closeexact fix written, re-checked until closed
Look-alike domainsMonitored
Monitorre-read every hour
Illustrative firm · read-onlyHuman-verified
The AI era

Two ways AI is used against you today.

The message

Attackers use AI to write convincing fraud.

Fake invoices, cloned voices and messages that sound like you, tailored from what is public about your business.

How it works

Your free reading shows whether anyone can forge mail in your name.

The ways in today
The research

Attackers use AI to research you.

It reads your website and staff pages to learn who approves payments and who your suppliers are.

Organised fraud groups also run AI built without safety limits.

Your free reading shows what an attacker can see from outside.

Business email compromise (BEC)
$3,046,598,558

Reported losses to business email compromise in the United States in one year: a scam that uses a hijacked or imitated business email account to get a payment sent. 24,768 complaints, 2025.

Source: FBI IC3 2025 Internet Crime Report, 2025. Reported losses only.

Check my firm

There’s only one answer to AI-powered attacks: AI-powered defense.

More than one door

A forged invoice, the attacker’s AI behind it, six ways in, and each one found, with its fix, and checked again from outside.

Words on screen, no voice. Illustrative firm.

Read the transcript
  1. Invoice 2217: new bank details. From [email protected]. Paid · $48,200. Your firm never sent it.
  2. How did they get in? Attacker’s AI agent: Attackers now send AI agents. Find firms to impersonate. 4,000 firms read. Copy of your address: set up. (harbourview-llp-pay.example) Invoice written in the partner’s style. Sent. (Illustration.)
  3. Copy of your address: set up. (harbourview-llp-pay.example) Mail from it looks like yours.
  4. Staff emails in leaked lists from hacks.
  5. A remote-access door, open to the internet.
  6. A private file, readable online.
  7. Software with a public weakness.
  8. Email anyone can fake.
  9. Six ways in.
  10. Their AI agents check every door.
  11. At every firm.
  12. LeakTrace checks from outside.
  13. Never your email or files.
  14. LeakTrace finds each one.
  15. Hands you the exact fix. Step by step, for whoever runs IT.
  16. Checks again from outside: closed.
  17. A copy isn’t yours to switch off.
  18. LeakTrace watches it, and every new one.
  19. LeakTrace checks for new copies every hour.
  20. The AI defense layer. See what’s open at your firm. Enter your website. Results by email. Free. Check my firm · getleaktrace.com
The good news

Anything an attacker can see from outside, we can find and close first.

Attacks on businesses like yours still start with something anyone on the internet can see: a mail setting that lets forgeries through, a staff password in a breach database, a look-alike domain, an open sign-in page. Each of those can be found before an attacker uses it.

24/7 Monitored day and nightRe-checked every hour on monitoring
1 h First to knowAlerts within the hour on hourly checks
The difference

Every finding, proven.

Each finding we show carries the record behind it and a check anyone can re-run, your insurer included. Human-verified before it reaches you.

Counted from our own records as of 10 Oct 2026, 23:59 UTC, refreshed hourly. Illustrative items are labelled.
237.5K

Look-alike domains checked

Brand impersonation caught within the hour it goes live, on monitoring.

186K

Certificate records read

New host names on your domain found as they are certificated, re-checked hourly on monitoring.

2,653

Firms read from outside

Each read the way an attacker’s tools read it, from public sources, logged into nothing.

Show moreShow less
1 clickTo protect your name against forged mail, where we can reach your DNS host
Newest on the exploited list
ProFTPD ProFTPDAdded 8 Oct · ProFTPD Improper Access Control Vulnera…
ISC BINDAdded 8 Oct · ISC BIND Data Processing Errors Vulnera…
Apache StrutsAdded 8 Oct · Apache Struts Command Injection Vulnera…
1 dayTo match a newly exploited flaw to the software a monitored firm’s site shows
5,261Public disclosures indexed, each with the way in. Updated daily
2,649Firms whose addresses were checked against monitored breach databases
72 hFrom confirmation to a human-verified assessment
Public sources only
Your websitePublic
Your mail setupPublic
Public recordsPublic
Breach listingsPublic
0Log-ins to any client system. Each check is a public lookup, like this one.

Check my firm

How the AI defense layer works

Every way in, found first and closed.

Agent against agent: attackers point AI at firms, and LeakTrace reads them first. Continuous exposure watch, AI-driven and read from outside, in four stages: Discover, Validate, Close and Monitor. The next machine-speed attack finds the door already shut.

4 steps · click each
1 Discover1 Discover

Discover every way in

Found from outside, the way an attacker’s tools read it. Nothing to install, no access to give.

On a paid assessment, the Discover AI agent reads what your firm shows the public internet with fixed checks, records each finding with its evidence and chooses follow-up checks.

5Exposure classes watched, from forged mail to breach data
HourlyMail settings, look-alikes and new host names re-checked, on monitoring
What we monitor
Email impersonationEach gap in the records that say who may send mail as you, found and closed
Brand impersonationLook-alike domains caught within the hour they go live, and, if it is not yours, a takedown request drafted
Attack surface discoveryNew systems exposed on your domain, found as they appear
Exploited vulnerabilitiesFlaws attackers are actively using, matched to your website’s software within a day
Credential exposureAddresses at your domain in breach data, flagged before the passwords are reused
2 Validate2 Validate

Validate every finding

The exact record behind each finding, a check anyone can re-run, and human verification before release. Every paid assessment carries a signed record anyone you hand it to can verify in one step.

Every finding is kept with the record that proves it. A person reads the assessment before release.

EveryPaid assessment is checked by a person before release
72 hFrom confirmation to an approved assessment
Verify a record
Evidence behind each findingThe exact record, header or listing behind it
Signed assessment recordDated, and verifiable by anyone you hand it to
Tamper-evident recordEach approval, alert and DNS change hash-chained and verified daily
Anti-impersonation checkAnyone can confirm in one step that a message really came from us
3 Close3 Close

Close each opening

Forged email, the opening we find most, closes in one click where we reach your DNS host: staged, re-checked, nothing changed until you confirm. You get the fix for the rest, step by step, and we re-check until it is closed.

On a paid assessment, the Close AI agent gives you the fix for each finding and, for an email record, sets the steps out with your DNS host's own screens where we hold its guide. When you mark a fix done, AI chooses when to re-check, and only a fresh outside read closes it.

1 clickProtects your name against forged mail, where your DNS host is one we reach
Pre-filledThe outside questions on your cyber application
How it works
One-click mail fixWhere we can reach your DNS host; the exact records where we cannot
Takedown request draftedFor a look-alike worth a look that you say is not yours, for you to send
Patch before it is usedNewly exploited flaws matched to your software, with the fix
Insurance questions pre-filledThe outside questions on your cyber application, with the evidence
4 Monitor4 Monitor

Monitor around the clock

Re-checked every hour, 24/7, with alerts within the hour. You are first to know, before a client, a bank or an insurer.

On monitoring, fixed checks re-check your email settings, look-alike domains and new host names every hour, and everything else every day. The Monitor AI agent puts first the change that needs you, with a plain reason when it has one.

1 hAlerts within the hour on hourly checks, by email, Slack or Teams
24/7Monitored day and night; the same day for daily checks
For businesses
Alerts within the hourThe way in, in plain words: hourly checks within the hour, daily ones the same day
Slack or TeamsAlerts where your partners already talk
Board-ready summaryBoard-ready exposure summary, monthly
Peer benchmarkYour exposure ranked against others in your sector, where 30 or more are measured
The ways in that matter most

The ways in today, and our answer to each.

We can check three of these seven completely from outside, and three partly. The last one needs someone to look inside your systems, and we tell you that plainly.

The way inOur figureWhat we doCoverage
Email forged in your nameFake invoices and changed bank details, sent as you.
3 in 4professional firms cannot stop a stranger sending email in their name.LeakTrace index, readings to 8 October 2026
  • Discover: the setting that lets forged mail through.
  • Validate: with the public record behind it, dated and checkable by anyone.
  • Close: in one click where we reach your DNS host; the exact record where we cannot.
  • Monitor: re-checked every hour.
CoveredFrom outside, end to end.
Stolen or reused passwordsAn address at your domain in a breach database, and a password used again.
2 in 10professional firms have a shared address such as info@ in monitored breach databases.LeakTrace Research · Measured 30 Sep 2026
  • Discover: which of your addresses appear, with the source and date of each.
  • Monitor: re-checked every day.
Covered
Look-alike domains used to impersonate youA domain made from your name, set up for mail, with no website.
4 in 10professional firms have a look-alike of their domain registered and live.LeakTrace Research · Measured 30 Sep 2026
  • Discover: registered domains made from your name, each one we raise with its public record.
  • Validate: only what we observed, and one question: is it yours?
  • Close: a takedown request drafted, ready for you to send.
  • Monitor: re-checked every hour for new ones.
Covered
Known flaws attackers are exploiting nowNewly listed flaws in the software a website runs.
1,739Actively exploited flaws we watch forCounted from our own records
  • Discover: matched to the software your website shows, within a day of being listed.
  • Monitor: each new listing, daily.
PartlyYour website only.
Exposed sign-in pages and remote accessPortals, admin pages and remote-access ports anyone can reach.
  • Discover: which sign-in pages answer from outside, and which remote-access ports are open on your website’s host.
PartlyWe cannot see from outside whether multi-factor sign-in is switched on. Your IT provider can, and we tell you to ask them.
AI-written phishing and impersonationEmails that AI tailors to the person who receives them.
  • Close: forged mail in your name, as above.
PartlyA convincing message sent from some other address goes straight to your people, and no setting of yours can block it. We tell you that plainly.
RansomwareIt usually gets in through one of the openings above.
  • Close: those outside openings, one by one.
Not visible from outsideWe cannot see your backups or internal systems from outside, and we tell you so.

Figures are LeakTrace Research, measured across the businesses we have assessed, each with its date. Everything here comes from public sources only.

The latest · 10 Oct 2026

How they got in this week, and what we watch for you.

United StatesPublic source9 Oct 2026SecurityWeek

Domino's

Way in
Stolen or reused passwords.
Our check
Addresses at your domain in monitored breach databases.
South KoreaPublic source8 Oct 2026BleepingComputer

Uranium Finance

Way in
A known flaw in software the victim ran.
Our check
Software versions your site advertises and known flaws in them.
LeakTrace Research

What anyone can see about professional businesses, measured.

See the research
  1. Nearly9 in 10

    dental practices cannot stop a stranger sending email in their name.

    LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records
Show allShow less
  1. Nearly9 in 10

    dental practices cannot stop a stranger sending email in their name.

    LeakTrace index, readings to 8 October 2026 · 88.4%, read from each firm's public mail records
  2. Nearly5 in 10

    accounting firms have a look-alike of their domain registered and live.

    LeakTrace Research · measured 30 Sep 2026 · 46.4%, common misspellings checked in public DNS
  3. 3 in 10

    accounting firms have a shared address such as info@ in monitored breach databases.

    LeakTrace Research · measured 30 Sep 2026 · 28.9%, shared addresses checked in monitored breach databases
The rules you answer to

Every finding, mapped to the rule you answer to.

A pen test covers what it is scoped to, once. Every assessment runs up to 37 outside checks. We hand you the record your regulator, your insurer and your partners ask for.

FindingEmail forged in your name
RuleABA Model Rule 1.6 and FTC Act Section 5The duty to protect client information; your state bar adopts its own version.
You getThe dated record, the fix (one click on the DNS hosts we reach) and the outside re-check that confirms it closed.
Show allShow less

Law

FindingEmail forged in your name
RuleABA Model Rule 1.6 and FTC Act Section 5The duty to protect client information; your state bar adopts its own version.
You getThe dated record, the fix (one click on the DNS hosts we reach) and the outside re-check that confirms it closed.
FindingFirm addresses in breach databases
RuleABA Model Rule 1.6 and state breach notification lawsNotice when personal information is exposed; timing varies by state.
You getThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Does your domain enforce DMARC at quarantine or reject?
RuleYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
You getWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Accounting

FindingFirm addresses in breach databases
RuleFTC Safeguards Rule, 16 CFR 314.4Multi-factor sign-in for anyone accessing customer information.
You getThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingEmail forged in your name
RuleFTC Safeguards Rule, 16 CFR 314.4A security program that safeguards customer information.
You getThe dated record, the fix (one click on the DNS hosts we reach) and the outside re-check that confirms it closed.
FindingInsurer asks: Are staff email addresses clear of known breach data?
RuleYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
You getWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Medical

FindingEmail forged in your name
RuleHIPAA Security Rule, 45 CFR 164.308Administrative safeguards for patient health information.
You getThe dated record, the fix (one click on the DNS hosts we reach) and the outside re-check that confirms it closed.
FindingStaff addresses in breach databases
RuleHIPAA, 45 CFR 164.404Tell patients of a breach within 60 days of discovery.
You getThe addresses we can name, the breaches they are listed in, and the record to keep: each password reset and multi-factor sign-in confirmed, dated.
FindingInsurer asks: Do you require multi-factor sign-in for email and remote access?
RuleYour cyber insurance applicationWe cannot see this from outside, and we tell you so.
You getWhat we did see that bears on it, so the answer you give is your own.

Wealth

FindingEmail forged in your name
RuleRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmWritten policies and procedures to safeguard customer records and information, including an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
You getThe dated record, the fix (one click on the DNS hosts we reach) and the outside re-check that confirms it closed.
FindingA look-alike of your domain, registered and live
RuleRegulation S-P, for SEC-registered advisers, and FTC Safeguards Rule, where it applies to your firmAn incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information.
You getEach one named; if it is not yours, a takedown request drafted with the evidence.
FindingInsurer asks: Do you keep internet-facing software patched and up to date?
RuleYour cyber insurance applicationThe insurer makes its own decision; the answer comes from the record.
You getWhere an outside read can answer it, the answer pre-filled from the evidence, with the record behind it.

Shown for the United States. Only the rules the Rules and Insurance Briefing maps; which one applies depends on your business, and your briefing names it.

All rules we map
FTC Act Section 5US

Safeguard consumer data. Failures are treated as unfair or deceptive practices.

SEC Regulation S-PUS

SEC-registered advisers and broker-dealers: an incident response program, oversight of service providers, and notice to affected customers no later than 30 days after becoming aware.

FTC Safeguards RuleUS

Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.

HIPAAUS

Covered clinics: protect patient health information and tell patients within 60 days of discovery.

State breach notification lawsUS

Notify affected people when personal information is exposed. Timing varies by state.

201 CMR 17.03US

Anyone holding a Massachusetts resident's data: review the written security program every year.

PIPEDACA

Safeguards appropriate to the sensitivity of the information. Notify of a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.

Alberta PIPACA

Prompt notice to the Commissioner where harm is a real risk.

BC PIPACA

Reasonable security arrangements against unauthorized access.

PHIPACA

Ontario health custodians: protect patient information and notify the Information and Privacy Commissioner of breaches.

The rules for your country come first. We list a rule only where we can say honestly whether it applies to you.

Who it is for

For those who hold other people’s money and confidences.

Show allShow less
Independence

Outside only. Independent, and answerable to you.

We read what you show the public internet, and nothing else. What we find goes to you alone.

Your IT provider keeps your systems running. We read your domain independently and show you what is open, each finding with its evidence.

A penetration test needs access to try to break in. We read only what is already public, and log into nothing.

Your insurer’s scan can feed your premium, and we do not see it. We show you first what anyone can see, so you walk into renewal knowing your own answers.

Access neededNone
Log-ins to your systemsNone
Mutual NDAAvailable on request
Questions
Nothing of yours. We read what is public, the way an attacker’s tools would. Our AI agents work from outside only. They never log in, never install anything, and never touch your internal systems. The one change they can make, to your email records, happens only when you approve it.

See your firm the way an attacker’s AI sees it.

Your outside reading: your email setup, your website, look-alike domains, staff passwords in breach databases and your sign-in pages, each with its evidence; the fix steps and an AI security agent on your dashboard come with the assessment. Free, read-only, and sent only to your work email.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request

A person reads every request. We reply within one business day from [email protected]. Privacy

The incidents that reach businesses like yours, and what to check, in one email. Sign up