A former core infrastructure engineer was sentenced to 32 months in prison for carrying out an extortion attack against his employer. The employee set …
Closing funds move on one email. Make sure the email is yours.
Wire instructions, payoff letters and closing figures all travel by email, and a buyer acts on the one that reads as yours. Attackers read your domain. We read it first and show you what is open.
Attackers now use AI to read a business from outside the way a search engine does: the website, directories, search results and what AI assistants say. Each finding we hand you is human-verified before your assessment is released.
The reporting deadlines that apply to you.
Notify affected residents when certain personal information is breached. Timing and content differ.
Report a breach that creates a real risk of significant harm to the Privacy Commissioner, and tell the people affected.
Notify the Commission d'accès à l'information and the people concerned of an incident that risks serious injury, and keep a register of every confidentiality incident.
A summary of published rules, not legal advice. The Rules and Insurance Briefing names the rules that apply to you.
Buyers, sellers and lenders act on every closing email you send. One forged wire instruction in your name costs a buyer the money for their home.
Nothing reported for this sector this week. What attackers used elsewhere, and what we check for it.
Payment fraud, from the public record.
A lawsuit filed in February 2026 says a title insurer closing a Rhode Island property sale in January 2026 wired $4.16 million of sale proceeds to a fraudster's account. It says the seller's lawyer later told it that an email account on the seller's side had been hacked before closing. That is a claim, not a finding.
In January 2026 Alberta's real estate regulator warned that, in a recent deal, a fraudster got into the email exchange between the buyer's and the seller's agents and sent a message that appeared to come from the seller's agent. The buyer sent the deposit where the fake message said.
A lawsuit filed in Delaware in January 2026 says a home buyer wired $2,209,240 for a closing after an email that claimed to be from the real-estate coordinator at her law firm. The claim says it came from a free webmail address. That is a claim, not a finding.
Each case is from the public source linked under it, in that source's own terms. LeakTrace had no part in any of them.
What changes after your assessment, and how often we look.
- 01A new vendor or tool is allowed to send as you.
- 02Your mail moves to a new provider.
- 03A new portal or subdomain goes live.
- 04A certificate lapses.
- 05Your addresses turn up in a fresh breach.
- 06A look-alike of your name is registered.
On monitoring: email settings, look-alikes and new host names hourly; everything else daily, with newly exploited flaws matched to your website’s software within a day and an alert the same day. The first month of monitoring comes with the assessment.
Human-verified. The full watch, the proof for every finding, and the fix.
What the fourth document is. A dated record of what was read from outside your business, verified by a person at LeakTrace before release. LeakTrace Inc. issues it as a company, with a reference and a fingerprint anyone can check at getleaktrace.com/verify/. No individual signs it. It is not a certification, not a penetration test, not legal or compliance advice, and not a statement about your internal systems.
We close it: We give you the fix for each finding and re-check from outside until it is closed.
The one change we can make ourselves is to your email records, and only when you approve each step, where your DNS host allows it.
Where it does not, you get the exact records to paste.
Your evidence pack:
- an owner summary
- the technical evidence with the fix for each finding
- a rules and insurance briefing
- a signed assessment record
It doubles as your insurance renewal evidence pack:
- the insurer’s questions that an outside read can answer, pre-filled from the evidence
- forged-email protection where we reach your DNS host, one click per step
- where you have a forged-email finding, a personal video of it to forward to the partners and the broker
The assessment comes with an AI security agent on your dashboard: ask it about any finding in plain English and it answers from your own business's findings.
Our AI agents work from outside only. They never log in, never install anything, and never touch your internal systems.
The one change they can make, to your email records, happens only when you approve it.
See what is open before anyone else does.
We read from outside, find each way in first, and show it with a check anyone can re-run. No access, nothing tested, no obligation.
- We read your business from outside.
- You see what is open, with the proof for the lead finding.
- If it is worth it, you order.
What happens if you go ahead. More at getleaktrace.com/see-it-first/.
Read the transcript
- 72 hours. One domain. Nothing to install.
- Discover. Every way in, found from outside.
- Validate. Proof, not scores. Dated and checkable by anyone.
- Close. Forged email: one click, where we reach your DNS host and you approve it.
- You get the fix for the rest, step by step, and we re-check until it is closed.
- Monitor. On monitoring: re-checked every hour, 24/7. Alerts within the hour.
- Every paid assessment is human-verified before release.
- The AI defense layer for businesses. See it first. getleaktrace.com/see-it-first/