In plain words
When a website a staff member signed up for suffers a breach, its list of addresses and passwords is often copied and shared. If that person used the same password for their work email, anyone holding the list can try it. Your firm was never broken into; the password simply became public somewhere else.
How credentials become exposed
- Breaches at other companies. A staff member uses a work address to sign up for an online service. That service suffers a breach, and its user list is copied and passed around.
- Password-stealing software. Malware on a personal or shared computer can copy the passwords saved in a browser, along with the sites they belong to.
- Files published by mistake. Settings files, keys or passwords are sometimes left in a website's own code or in open cloud storage.
Why it matters to a firm
People reuse passwords. A password exposed with a work address can open email, remote access or cloud files if it was reused there. Automated tools try exposed address and password pairs against other services at scale, so the time between exposure and a sign-in attempt can be short.
If an exposed password leads to access to personal information, a breach-reporting duty can follow: under PIPEDA in Canada, and under state breach-notification laws in the United States.
What we read
Monitored breach databases and paste sites, and keys left in your own website's code. We do not log in to anything, and we do not visit criminal forums.
How often
For firms we monitor, a re-check every day, and a new exposure reaches you the same day we find it. A one-time External Cybersecurity Assessment reads it once and dates it.
What to do when an address is exposed
- Change the password on the exposed account and on every account where the same password was used.
- Turn on two-step sign-in for email first, then for remote access and cloud files.
- Ask your IT provider to review recent sign-ins and any new mail-forwarding rules on the account.
- Check whether the exposure touches personal information you hold, and whether a reporting duty applies.
Check one address now
Our free address check reads one email address against breach records and tells you what to do first: getleaktrace.com/individual.
- Personal Information Protection and Electronic Documents Act (PIPEDA), s. 10.1, breach of security safeguards, Government of Canada
- Office of the Privacy Commissioner of Canada, guidance on mandatory breach reporting