This briefing lists kinds of business data that are routinely stolen and resold, and sets out what a business can check from the outside. It is a reference list for July 2026, not a count of listings, and it does not name or identify any business or person.
How LeakTrace looks
Everything LeakTrace checks is external and passive. We read monitored breach databases for a business's email addresses, the public DNS and email settings that decide whether someone can send mail in its name, its public web pages, and look-alike domains registered against its name. We do not buy, download or redistribute stolen data.
Categories of business data to check for
Use the list to ask one practical question: which of these does your business hold, and where does it live?
- Dental practice patient records
- Home services provider customer records
- Bookkeeping firm client lists
- Property management tenant records
- Real estate transaction records
- Real estate closing files
- Physiotherapy clinic patient files
- Independent retailer customer databases
- Payroll and HR exports
- RIA wealth advisor client contact lists
Why it matters
American businesses and consumers reported $20.9 billion in losses to internet crime last year across more than a million complaints, and business email compromise alone accounted for $3.05 billion of it. Most of that fraud starts with something visible from outside the business: a staff login already in a breach database, or an email domain anyone can impersonate.
A category appearing in this list does not mean any specific business has been breached. It means that type of record is worth knowing the location of before somebody else asks.
What to do next
Review your access controls, backup posture, and third-party integrations. If any of the categories above match data your organization holds, confirm who can reach it and whether the logins that protect it have turned up in a breach elsewhere.
To see whether someone can send email that looks like it came from your domain, request your outside reading at /business/: we read your firm from outside, including the email records that decide whether mail in your name can be forged, and send the reading to a work email at your domain.
LeakTrace research describes what can be read from outside across the firms we assess. No client is named and no engagement is described. Where a percentage appears, it describes the firms in our view, not a national census.
We will add you to the distribution list. To come off it, email [email protected]. Privacy policy.