Summary
LeakTrace assessed the public surface of 2,305 American owner-run firms from April to July 2026: email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl, lookalike domains and keys left in website code. The average external Rating across those 2,305 firms was 95.1 of 100, and 96.8% of them were rated Critical or High.
Owner-credential exposure was measured for 3 firms in this population, too few to publish a rate.
This report gives the sector and regional breakdowns, the method, and the mitigation steps that apply across sectors. Every firm in the population was assessed from outside, before any engagement, using public data only.
Findings at a glance
Owner-credential exposure was measured for 3 firms in this population, too few to publish a rate.
External exposure
How the 2,305 firms assessed fall across the four severity bands, from outside checks of email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl and software versions.
| Severity band | Share of 2,305 | |
|---|---|---|
| Critical | 93.7% | |
| High | 3.2% | |
| Moderate | 3.2% | |
| Low | 0% |
How firms were exposed
Share of the 2,305 firms assessed where each condition was found, most common first.
| Condition | Share of 2,305 |
|---|---|
| Infrastructure misconfigurationsDNS, TLS/SSL, DMARC, SPF, or DKIM configurations flagged as high-risk during external scanning. | 100.0% |
| JavaScript secret exposureAPI keys, tokens, or credentials embedded in front-end JavaScript bundles reachable from the homepage. | 73.0% |
| Registered typosquat domainsLook-alike domain variants already registered by third parties, brand impersonation and BEC infrastructure. | 60.3% |
| WordPress user enumerationWordPress installations leaking usernames through unauthenticated REST endpoints, enables targeted credential-stuffing. | 41.3% |
| Exposed configuration endpointsPublicly-accessible admin panels, config files, or unprotected API endpoints identified via non-invasive probing. | 25.4% |
| Sensitive open portsInternet-facing ports exposing services with known CVEs or authentication concerns, per public internet indexes. | 20.6% |
| Vulnerable JavaScript librariesFront-end libraries with known CVEs loaded on production pages, direct client-side outside exposure. | 15.9% |
| Cloud storage exposurePublicly-listable S3/GCS/Azure buckets associated with the domain, data exfiltration risk. | 15.9% |
By sector
“Firms” is the number assessed in each sector as stored; the Rating runs from 0 to 100, and a lower rating is better. Owner-credential rates are not broken out by sector because the counts are too small to publish.
| Sector | Firms | Rating | Critical or High |
|---|---|---|---|
| Healthcare | 1957 | 96.0 | 95.2% |
| Legal | 279 | 94.3 | 100.0% |
| Dental | 29 | 96.2 | 100.0% |
| Other | 23 | 95.2 | 95.7% |
| Law | 17 | 91.2 | 94.1% |
By state
“Firms” is the number assessed there. Differences reflect the mix of firms as much as their upkeep.
| State | Firms | Rating | Critical or High |
|---|---|---|---|
| Texas | 1411 | 94.0 | 95.5% |
| Illinois | 575 | 90.7 | 92.9% |
| Washington | 279 | 100.0 | 100.0% |
| New York | 20 | 99.1 | 100.0% |
| Pennsylvania | 8 | 98.1 | 100.0% |
| California | 5 | 100.0 | 100.0% |
Recommended mitigations
For American owner-run firms in this monitoring population:
- ImmediateOutside exposure remediation
With an average external threat surface risk score of 95.1/100 and 96.8% of businesses classified as Critical or High risk, outside exposure reduction is the highest-leverage single investment. Priorities: enable DMARC enforcement, remediate SSL/TLS misconfigurations, retire exposed administrative interfaces, and review subdomain sprawl.
- ImmediateForce password rotation for owner/executive accounts
Owner and executive credentials appearing in known breach databases enable credential stuffing attacks as a realistic near-term threat. Rotating passwords + enabling MFA closes this vector immediately.
- Near-term (30 days)Deploy business email compromise (BEC) monitoring
Owner email addresses in breach databases enable BEC / whaling attacks where attackers pose as the executive. Monitoring for spoofed sender activity + implementing DMARC enforcement mitigates this.
- Near-term (30 days)Employee awareness training
Given the elevated infrastructure risk profile observed across the American owner-run firm landscape, staff awareness training is the highest-leverage human-factor investment. Focus on recognizing phishing, verifying wire requests, and reporting suspicious contact.
- QuarterlyRepeat the exposure check
Breach databases update daily and infrastructure changes affect risk scores. Quarterly re-checking is standard threat intelligence hygiene.
- StrategicCyber insurance review
With the elevated infrastructure exposure profile observed across the American owner-run firm landscape, cyber insurance policies should be reviewed for adequate coverage. Current premiums assume active mitigation programs; documented mitigation reduces premiums.
Visibility
LeakTrace maintains an ongoing threat intelligence pipeline monitoring American owner-run firms across sectors including healthcare, legal, financial services, and professional services. Our monitoring combines public data sources with proprietary discovery workflows and covers firms assessed before any engagement.
Coverage dimensions
- Infrastructure, outside exposure checks covering DNS security posture, TLS/SSL configuration, exposed administrative interfaces, subdomain sprawl, and vulnerable framework detection.
- Credential exposure, matching owner and executive email addresses against monitored breach databases and data-class exposure classification.
- Public web exposure, open-source intelligence aggregation covering code repository leaks, paste site mentions, and publicly-indexed disclosure activity.
Sources
- Monitored breach databases
- Supplementary monitored breach databases
- Open-source intelligence aggregation of publicly-indexed web content
- Publicly-available corporate registry data and business directories
- outside exposure checks across DNS, TLS, subdomain, and framework layers
Methodology
For each business in our monitoring pipeline, we run parallel exposure checks across the coverage dimensions above. Infrastructure risk scores are computed on a 0-100 scale where higher indicates greater exposure surface. Severity bands are harmonized across dimensions.
Limitations
- Public data only, no dark web or non-licensed sources
- Infrastructure reading is non-invasive, passive external observation only
- Severity indicates exposure surface, not active threat targeting
No firm is named. Every firm was assessed from outside, before any engagement, from public data only.
The outside watch for your firm: see what is open before anyone else does, with the proof for the lead finding. Check my firm →