Our thesis

Silence is the business model of the problem.

Almost everyone who knows about a breach has a reason not to mention it. The victim is ashamed, the company is exposed, the vendor is liable, and the story is not new enough to run. The information exists. It just never reaches the person it is about.

01

The number everyone quotes is a floor, not a total.

In 2025 the FBI’s Internet Crime Complaint Center recorded $20.877 billion in reported losses across 1,008,597 complaints — the first year complaints have ever passed a million. In Canada the same year, reported fraud losses hit a record $704 million.

Both figures count only the people who came forward. And the Canadian Anti-Fraud Centre publishes an estimate of how many that is.

Reported losses are 5–10% of the total
Not our estimate. The agency that collects the number says the number is a fraction of the problem — which means the real figure on both sides of the border is something between ten and twenty times what gets published.
02

Four parties know, and none of them are going to tell you.

The individual stays quiet out of embarrassment. Fraud is one of the few crimes where victims blame themselves, so it goes unreported and unmentioned — often not even to family.

The business stays quiet to protect its reputation. A practice that admits losing patient records loses patients. The commercial incentive runs directly against disclosure.

The breached platform grades its own homework. Canada has required breach reporting under PIPEDA since 2018, and all fifty US states have notification laws. But the trigger is whether the breach poses a real risk of significant harm — and the company that was breached is the one who decides. The rule exists. The judgment sits with the party least motivated to make it.

The press covers scale and novelty. A dental practice in Guelph losing its patient database is not a story. Ten thousand of them is not a story either, because it never happens on a single day.

03

“It hasn’t happened to me” usually means “I have not found out yet.”

Intrusions sit undetected for months. The absence of evidence that most people read as safety is, more often, the time between the breach and the discovery.

And your own hygiene cannot fix the largest part of the risk. Your data sits with dozens of third parties — an app, a carrier, a payroll provider, a booking system, a bank. You can have perfect passwords and still be exposed because a vendor you have never heard of was compromised. That is the argument for monitoring rather than hardening alone: hardening protects what you control, monitoring covers what you do not.

Credential reuse is what turns one company’s breach into your problem. A password exposed somewhere forgettable becomes access to something that matters. It is also why an owner’s personal exposure is a business risk, not a private one.

04

The economics favour the attacker, and AI widened the gap.

An attempt costs the attacker close to nothing. A hit can cost a small business everything. That asymmetry is why “we are too small to be a target” is backwards — small is precisely the target, because it is cheap to try and rarely defended.

The old defence was noticing bad grammar. That is gone. Fluent, personalised, correctly-localised phishing now costs nothing to produce at volume, and voice cloning is good enough to survive a callback. In 2025 the IC3 logged 22,364 complaints involving AI, accounting for more than $893 million in losses — the first year it was counted separately.

05

What follows from it.

If the information exists but never arrives, the useful thing to build is not more advice. It is delivery. Someone has to watch the places this surfaces and tell the person it belongs to, before the consequence does.

That is the whole company. We monitor breach corpora and public infrastructure, we find what is already exposed for a specific business or person, and we say so plainly — with the evidence attached, whether or not it leads to a sale.

You hear it from us first.

Not from your bank, not from a headline, and not from a customer asking why their details turned up somewhere. That is the standard we hold ourselves to, and it is the reason the free check exists at all.

Run the free exposure check →

Sources
  • Canadian Anti-Fraud Centre, 2025 annual figures — $704M reported; CAFC states reported incidents represent an estimated 5–10% of the total.
  • FBI Internet Crime Complaint Center, 2025 Internet Crime Report — $20.877B in reported losses, 1,008,597 complaints, 22,364 AI-related complaints totalling $893M+. ic3.gov
  • PIPEDA breach-reporting obligations, in force November 2018; US state notification statutes, all fifty states.

Figures are the most recent published at the time of writing. Where a number is reported rather than measured, we say so.

Enterprise-grade exposure intelligence for firms Fortune 500 vendors won't serve.

1200 Bay Street, Suite 1201
Toronto, ON M5R 2A5, Canada

228 Park Avenue South
New York, NY 10003, USA

© 2026 LeakTrace Inc. All rights reserved.

LeakTrace provides exposure intelligence and informational reports only. We are not a law firm or insurance company. Our reports are based on publicly available information and monitored breach databases and do not constitute legal, financial, or security advice. No service can completely eliminate the risk of identity theft, data breaches, or cyber fraud. LeakTrace makes no guarantees of prevention, detection, or recovery of losses.