This week
Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
The outside watch · Canada and the United States

The outside watch for your firm.

We watch what anyone on the internet can see about your firm, tell you first when something opens, prove every finding with a check you can run, and help you close it. We start where an attacker starts: outside. No software to install, no access to give, no meeting first.

Read-only, from outside Nothing logged into Reviewed by a person 72 hours from confirmation
Reading · your-firm.comIllustrative
Exposure score
58 / 100
Moderate
Domain and email3 open
Staff addresses in breach databases14 found
Website software1 open
Lookalike domainsWatch
Reviewed by a personRead-only
Why now

See what your underwriter sees, before you sign.

Insurance renewal forms ask about email authentication, multi-factor sign-in, backups and patching. Then there is wire fraud: someone can send email as your firm. Then your regulator or professional body. Most break-ins start with something anyone could see.

We watch your firm the way an attacker’s tools would: email that can be forged in your name, staff addresses in monitored breach databases, look-alike domains, and how those combine into a way in.

Reported losses to business email fraud reached $3,046,598,558 in 2025 in the United States (FBI IC3 2025 Internet Crime Report), and Canadians reported $67,900,000 CAD lost to spear phishing in 2025 (Canadian Anti-Fraud Centre). Every week we log how firms like yours were reached, and the finding that would have shown it first: this week’s incidents.

United States: In 2025 the FBI received more than 22,000 complaints reporting AI-related information, with adjusted losses over $893 million. FBI IC3, 2025 Internet Crime Report. Canada: The Canadian Centre for Cyber Security says AI technologies are “almost certainly lowering the barriers to entry” for malicious cyber activity. National Cyber Threat Assessment 2025-2026.

Breaches that began with a stolen or reused login
22%
Verizon DBIR 2025, 9,891 breaches with a known way in
Breaches that began with a known, unpatched flaw
20%
Verizon DBIR 2025, 9,891 breaches with a known way in
Breaches with a third party involved
30%
Verizon DBIR 2025, share of all breaches analysed

Source: Verizon Data Breach Investigations Report, 2025.

23%
Firms assessed with at least one staff address in monitored breach records
of 2,507 firms assessed, April to October 2026
79%
Firms assessed whose email can be forged in their name (no DMARC enforcement)
of 2,512 firms assessed, April to October 2026

So you see it before they do.

Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before you see it.

Read from outside, from public sources only. Illustrative items are labelled.
6Public groups read from outside, each with a check anyone can run
Openings foundIllustrative
Email forged in your nameNo DMARC policy published
Reused staff passwordsAddresses in older breaches
Lookalike domainOne letter off your own
4Openings shown in your free outside reading, with one check you can run yourself
23%Firms assessed with a staff address in breach recordsof 2,507 firms assessed, April to October 2026
0Log-ins, tests or access to your systems. None, ever.
72 hConfirmation to reviewed assessment
Illustrative
001$ dig TXT _dmarc.your-firm.com
002;; ANSWER: 0
003$ dig TXT your-firm.com
004"v=spf1 include:mail ~all"
005$
1Check you can run yourself, in your free outside reading
This is already public
United States
$3,046,598,558

Reported losses to business email fraud in one year. 24,768 complaints, 2025.

Source: FBI IC3 2025 Internet Crime Report, business email compromise, 2025. Reported losses only.

Canada
$67,900,000

Reported losses to spear phishing in Canada in one year. 813 reports, 2025, in CAD.

Source: Canadian Anti-Fraud Centre, spear phishing, 2025. Reported losses only.

01 · Who it is for

Two ways in. Both start free.

For firms

A free External Exposure Check on your domain, then the assessment if it is worth it.

Law and accounting firms, clinics, advisers, brokers and brokerages. Your outside reading shows four openings and a check you can run yourself.

For individuals

Is your email address in a public breach?

A free check against monitored breach databases, with what each breach exposed and what to do first.

02 · What we read

Six things anyone can check. We check them first.

01

Email that can be forged in your name

Anyone can check: look up your DMARC record with a free DNS tool.

02

Staff addresses in breach databases

Anyone can check: search an address on a public breach-notification service.

03

Lookalike domains

Anyone can check: type your domain with one letter changed.

04

What your website advertises

Anyone can check: read the response headers in your browser.

05

Public records, and keys left in your site’s code

Anyone can check: search the public business registry, and open your site’s page source.

06

What AI assistants say about you

Anyone can check: ask one who your firm is and what it does.

What one assessment found · Illustrative

So you can fix the right thing first.

Critical
14addresses
j•••••@your-firm.ca · 2023 breachPassword
[email protected] · 2021 breachPassword
m•••••@your-firm.ca · 2019 breachPhone

Staff addresses in breach databases

Which addresses, which breach, what it exposed, and who should reset first.

High
3settings open
SPFToo loose
DKIMMissing
DMARCNot enforced

Email forgery

The settings that let someone send as you.

High
6lookalikes
your-frim.caMail ready
yourfirm.caParked
your-firm.coParked

Lookalike domains

Registered names one letter off yours.

Medium
1out of date
Site builder 5.8Update
Contact form pluginCurrent
Security certificateCurrent

Website software

Versions your site advertises to anyone.

Low
2wrong answers
“The firm is at 12 Queen St.”Old address
“Open Saturdays”Wrong
Practice areasCorrect

What assistants say

How AI tools describe your firm.

Illustrative reading of a firm that does not exist. Your own outside reading shows your own domain.

One assessment. The evidence behind the watch, each piece for the person who acts on it.

Owner summary

For the person who signs off: what is open, what it could cost, and who does what this week.

3Fixes first, in order
30Days watched, same-day alerts
What is in it
Read
What is open, in plain words
Decide
Three fixes, in order
Assign
Who fixes each item
Track
Watched continuously for the included month

Technical evidence

For your IT provider: what we saw, where we saw it, and the change that closes it.

Every finding with its evidence and checkFix steps for most findings
0Fixes performed by us
What is in it
Evidence
Record, header or listing
Severity
Critical to low, with reason
Fix
Step-by-step change, where one exists
Check
How to confirm it worked

Rules and insurance

Each finding mapped to the rule you answer to, and the questions insurers ask at renewal.

50US states with breach notification laws
24Months a breach record is kept (PIPEDA, Canada)
Up to 6Insurer questions, answered from the checks
What is in it
Law
Named for your province or state
Regulator
Who can ask
Insurer
Renewal answers ready
Record
What to keep on file

Signed record

A dated, signed assessment record you can hand to an insurer, a client or a regulator, and that anyone can verify.

Issued by LeakTraceDated and signed
Verifiable at getleaktrace.com/verifyReference anyone can check
What is in it
Dated
Point-in-time attestation
Signed
Reviewed by a person
Verifiable
Reference anyone can check
Private
Shared only by you

Findings arrive mapped to the rule that applies to you

FTC Act Section 5US

Safeguard consumer data. Failures are treated as unfair or deceptive practices.

FTC Safeguards RuleUS

Tax preparers, mortgage brokers and other financial institutions: multi-factor sign-in, and notice to the FTC within 30 days of a breach of 500 or more people.

HIPAAUS

Covered clinics: protect patient health information and tell patients within 60 days of discovery.

State breach notification lawsUS

Notify affected people when personal information is exposed. Timing varies by state.

201 CMR 17.03US

Anyone holding a Massachusetts resident's data: review the written security program every year.

PIPEDACA

Safeguards appropriate to the sensitivity of the information. Report a breach that creates a real risk of significant harm, and keep a record of every breach for 24 months.

Alberta PIPACA

Prompt notice to the Commissioner where harm is a real risk.

BC PIPACA

Reasonable security arrangements against unauthorized access.

PHIPACA

Ontario health custodians: protect patient information and report breaches to the Information and Privacy Commissioner.

Only the rules the Rules and Insurance Briefing maps. A rule is listed only where its applicability can be stated honestly.

04 · What you receive

The proof for every finding, and the fix.

Your evidence pack: an owner summary, the technical evidence for your IT provider, a rules and insurance briefing, and a signed assessment record.

1

Owner Summary and Action Brief

The verdict, the fixes in order and what each one closes, written for the owner. Who does each fix, how long it takes, and the check that proves it is done.

Executive brief
2

Technical Evidence and Findings

Every finding with its evidence, its severity and the check that confirms it is closed. Step-by-step fixes for most findings. We perform none of them.

For your IT provider
3

Rules and Insurance Briefing

Each finding mapped to the rule that applies in your province or state and sector, the regulator who can ask, the insurer renewal questions a real check answers, and what to keep on file.

Statutory mapping
4

Signed Assessment Record

What was reviewed, when, what was found and what was closed, signed and dated, issued by LeakTrace. Anyone you hand it to can verify it at getleaktrace.com/verify.

Dated attestation
05 · How it works
1

You ask

Tell us your firm and domain. It takes a minute.

2

We read, we tell you first

From outside, public sources only. Your outside reading arrives, with proof you can check.

3

You decide

The reading shows what the assessment would cover. No obligation.

4

Delivered and reviewed

Inside 72 hours of confirmation, approved by a person first.

What the assessment does for the firm, long after it is read.

01

Helps win new clients

A signed, dated record answers the security questions larger clients now ask.

02

Ready for the insurer

The rules briefing matches the questions on a cyber insurance renewal.

03

Protects what the firm is worth

A clean record helps when a partner joins, leaves or buys in.

04

Stops the guessing

You know which openings exist, in what order to close them, and who does it.

06 · This week · 3 Oct 2026

How firms like yours were reached.

Public report2 Oct 2026SecurityWeek

Universities and private organizations in US

An Iranian national linked to the Mabna Institute was extradited to the US for participating in massive cyber intrusions targeting hundreds of organizations. The campaign affected 144 US universities, dozens of companies, and federal...

Public report2 Oct 2026Global News

Kingston Police

How they got in
Stolen or reused passwords.
What we check
Staff addresses present in monitored breach databases.
Public report2 Oct 2026SecurityWeek

US think tanks and universities

How they got in
Email made to look like it came from a trusted sender.
What we check
Whether anyone can send email that passes as your domain.
07 · Independence

We find it. Your IT provider fixes it.

So nothing in a finding is there to create work for us. Your existing IT provider does the fixes, from the steps we give them.

Your IT provider keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We do none of the fixes ourselves, so nothing we find is there to create work for us.

A penetration test tries to break in and needs access. We read only what is already public, from outside, and log into nothing.

Your insurer's scan feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.

Remediation soldNone
Access neededNone
Mutual NDAAvailable on request
08 · Questions
Nothing of yours. We read what your firm shows to the public internet, the way anyone could.

See what your firm looks like from outside.

A free outside reading, sent only to the address you give. No access to your systems.

What we readPublic sources only
Who sees itYou alone
Delivery72 hours from confirmation
Mutual NDAAvailable on request

A person reads every request. We reply within one business day from [email protected]. Privacy

Get this week's incidents, and what to check, when a briefing is published.

One email when a briefing is published. Unsubscribe in one click. Privacy

How one finding is read · no sound

Illustrative finding. No firm is shown.

Read the transcript
  1. p=none. Anyone can send email in your name.
  2. A public DNS record for a firm: its email authentication setting.
  3. The setting that fails: p=none. Email in the firm's name can be forged.
  4. p=none is monitor mode. Mail servers are told to report a forgery, not to stop it.
  5. Delivered in your firm's name: a forged invoice, a fake payment instruction, a request for client records.
  6. The fix in three steps: read the reports, move to quarantine, then reject.
  7. Forged mail refused. Your own email still delivered. One public record changed.
  8. 8 in 10 professional firms cannot stop an email sent in their name.
  9. One finding, read from outside. Every finding at your firm, in one assessment.