Two in ten of the professional firms we assess have at least one shared address on their own domain, info@, admin@ or contact@, present in monitored breach databases.

That does not mean the firm was breached. An address lands in these records when a service it was used with loses its user list: a supplier portal, a newsletter tool, a software trial. The firm's own systems may never have been touched. Depending on the incident, the record can include a password that was used with the address at the time, and these records are the material that account-takeover attempts start from.

What we measured

For each firm we looked up its common shared addresses against monitored breach databases, and counted the firm if at least one was present. A firm is counted only when every lookup was answered. Where a lookup went unanswered, the firm is left out of both sides of the figure: a check that did not run is not a clean result. Measured on 30 September 2026:

  • 21.4% of firms have at least one shared address present in monitored breach databases.
  • Of the addresses found, six in ten were info@ and nearly all the rest were admin@.

By sector

  • 28.9% of accounting firms.
  • 23.0% of real estate brokerages.
  • 18.5% of insurance brokerages.
  • 14.3% of law firms.

Why shared addresses matter

An address in breach records is only dangerous where it still opens something. The work is finding out what it opens.

A shared address is read by several people, printed on the website, and often used as the sign-in for something that matters: the domain registrar, the website, a banking or payments portal, a supplier account. Because several people use it, its password is often shared as well.

What to do

  1. List where each shared address is used as a sign-in. Start with the domain registrar, the website, email itself and anything that moves money.
  2. Change the password on each of those to one used nowhere else, and keep it in a password manager.
  3. Turn on two-step sign-in wherever a shared address is the login. On its own, this defeats a reused password.
  4. Where several people use one sign-in, give each person their own account instead, so access ends when someone leaves.

Method

No systems were accessed, no logins were used, and no firm, address or incident is named here or anywhere else. The population is owner-run professional firms in Canada and the United States that we have assessed: law, accounting, insurance, real estate and other regulated practices. We used the most recent assessment of each firm and removed test, demonstration and internal records and duplicate domains. Only assessments made between 24 and 30 September 2026 are counted, because those are the ones that record whether every lookup was answered, so this figure rests on a smaller set than our other studies: 359 firms, measured on 30 September 2026, 21.4%. Sector figures are shown only where at least 30 firms were assessed. We look up shared addresses, not named individuals, so the figure is a floor for each firm as a whole. Percentages describe the firms in our visibility, not a national census.