A Canadian business broker representing the seller in a mid-market professional-services acquisition engaged LeakTrace to run pre-sale cyber diligence before the buyer's diligence team commenced work. The engagement surfaced findings the buyer's cyber diligence would have identified within days of engagement, and the deal closed at the letter-of-intent terms without re-trade.

Engagement origin

The broker had recently seen a comparable transaction re-priced at the closing stage after the buyer's cyber diligence identified exposure conditions the seller had not disclosed in the confidential information memorandum. The broker's principal did not want to repeat that experience on the current listing. The seller was a mid-market Canadian professional-services firm with approximately seventy staff, active files across two provinces, and a client roster the buyer had explicitly cited as strategic in the letter of intent. The broker engaged LeakTrace directly on the seller's behalf and included the audit output as part of the seller's data room preparation rather than waiting for the buyer to raise cyber diligence at the closing stage.

Discovery scope

LeakTrace conducted a seventy-two-hour external attack surface audit covering the seller's registered domains, senior staff email patterns, the practice's public web presence, and the vendor relationships visible through DNS and certificate transparency records. Public directory records associated with the seller's professional registrations were reviewed for exposure conditions relevant to the specific regulatory regime the buyer would be inheriting. The engagement did not touch the seller's internal systems and was scoped to complete before the buyer's own cyber diligence engagement commenced.

Findings summary

  • Cross-location credential reuse. Senior staff email addresses appeared in monitored breach databases with recoverable password fragments. Password reuse was identifiable across the seller's primary business platform and its client portal. The pattern extended across both locations, indicating the exposure was a firm-wide practice rather than a single administrative lapse.
  • Client portal exposure. The seller's public-facing client portal was reachable without geographic access controls or bot mitigation. The vendor's version disclosure indicated the portal was running on a release that had received security guidance in the prior quarter that the seller had not applied.
  • Regulatory obligation timing. A subset of the credentials identified in the breach index would trigger notification obligations under the applicable provincial privacy regime if the seller's counsel evaluated them under a current risk-of-significant-harm framework. The obligation window would open once notification was assessed, and could not be transferred to the buyer through the transaction.
  • Vendor concentration risk. DNS records disclosed that the seller's outsourced information-technology provider serviced several of the seller's largest client relationships as well. A targeting attacker or a strategic buyer with access to that vendor mapping would have had a clear picture of the seller's concentration risk before opening the data room.

Seller actions

The seller remediated the identified exposure conditions before the buyer's diligence engagement commenced. Credentials appearing in the breach index were rotated and multi-factor authentication was enforced across senior staff. The client portal vendor's guidance was applied and the geographic access controls were configured. The seller's counsel reviewed the credential exposure findings against the provincial privacy regime and executed the notification assessment before the transaction data room was opened, so that any regulatory action would be documented as pre-transaction and would not become a post-close liability for the buyer. The vendor concentration risk was disclosed in the data room with the seller's proposed mitigation.

Outcome

The buyer's cyber diligence team completed its own engagement in the standard window and returned a diligence report substantively consistent with the audit output already in the data room. The buyer did not request a purchase-price adjustment on cyber diligence findings, and did not require an indemnity carve-out for the identified exposure. The closing occurred at the letter-of-intent terms. The seller's broker later engaged LeakTrace as a standing pre-sale referral partner on subsequent listings in the same class.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to the seller's internal systems, purchased breach data, or coordination with any threat actor. The seller's counsel reviewed all provincial regulatory findings prior to any action being taken. This case file documents the pattern of pre-sale cyber diligence engagements LeakTrace conducts with Canadian business brokers on professional-services listings, and is not attributed to the specific broker, seller, buyer, or transaction referenced.