Reference · LeakTrace Intelligence Team
Executive email addresses harvested from paste sites
Public paste-site archives contain executive email addresses paired with breached passwords, providing an off-the-shelf target list for BEC.
Pattern summary
- Category
- Paste site leak
- Severity
- High
- Prevalence framing
- Common across founder-led firms and family office principals with long email tenure.
- Remediation effort
- Moderate
- Verticals affected
- FamilyofficeWealthmanagementSportsLegalFinancial
Paste sites (Pastebin, Ghostbin, Anonfiles, Rentry, and their successors) get used by attackers to publicly stage credential dumps, mailing lists, and OSINT compilations. Executive email addresses — CEO, CFO, principal, chief of staff, general counsel — are the most valuable line items in those dumps because they map directly to wire-authority workflows.
## Why attackers exploit it
A pretext-attack chain starts with a target list. Paste-site scraping produces a target list for free. The attacker cross-references executive emails against LinkedIn seniority, company wire volume, and known advisor-tenant relationships (accountant, wealth manager, law firm) to pick the highest-yield targets before staging the actual attack.
## Remediation direction
Continuous paste-site monitoring with alerts on executive email addresses appearing in any new dump, plus a takedown workflow for content that hosting providers will honor. Executives themselves benefit from a personal email hygiene review — legacy accounts on breached consumer services are the entry vector for most paste-site inclusions.
Concerned this pattern touches your exposure surface?
LeakTrace runs continuous intelligence on principals, households, and advisor tenants across every observable public exposure surface. Discovery call under mutual NDA, first-touch reply within one business day from an authenticated LeakTrace address.
See services and pricing