// DATA BREACHES

What breach intelligence is

Breach intelligence is the monitoring and evaluation of data that has already leaked, meaning emails, passwords, and company details from leak databases and the dark web, so a company knows which of its credentials are publicly available before someone abuses them. It doesn’t break or bypass anything. It only collects what has already leaked. It isn’t a penetration test, and it isn’t reconnaissance of public sources before an attack.

// 01

Key facts

ItemDetail
What it isMonitoring of already leaked data against a list of your domains and addresses
What it monitorsCompany emails, domains, and credentials
Where the data comes fromPublic breach corpora, leak databases, dark web forums, and credential stuffing lists
What it is notNot hacking, not a penetration test, not OSINT
Public exampleHave I Been Pwned, a check of one address against known breaches
Primary sourceNIST CSRC: definition of the term breach

// 02

Where leaked data comes from

Leaked data doesn’t originate at the company it concerns. It originates from a breach of a third party: a service where someone had an account under a company email gets compromised, and its user database ends up out in the open. If the password was the same as the one for the company, company access is suddenly public without anything having failed at the company itself.

Breach intelligence collects these leaks from four kinds of source: public breach corpora that aggregate large past leaks, leak databases circulating around the internet, dark web forums where access is resold, and credential stuffing lists, meaning bulk lists of email and password pairs. What they have in common is that all of it has already leaked.

// 03

What breach intelligence is for

It serves one purpose: to find out which of your credentials are already publicly available before someone abuses them. A leaked password is a quiet way in, because a login with a valid account raises no alarm. Anyone who knows a specific account is out there can invalidate the password, enforce multi-factor authentication, and revoke sessions before an attacker reaches the account.

In practice it is a defense against account takeover and against the attacks that follow. Leaked company passwords are raw material for targeted phishing and for fraudulent payments, so how leaked passwords get abused is the other side of the same coin. The continuous form of this defense is data breach monitoring as a service.

// 04

What breach intelligence isn’t

It isn’t hacking. Breach intelligence breaks nothing and bypasses nothing. It works exclusively with data that has already leaked and lies in public or on the dark web. Dark web monitoring here means only reading the more closed-off places an ordinary search engine can’t reach, not an active intervention.

It isn’t OSINT, or open-source intelligence, either, and it isn’t a penetration test. OSINT is reconnaissance from public sources before an attack, which assembles a picture of the target from open information; breach intelligence looks more narrowly, specifically at credentials that have already leaked. A penetration test, in turn, actively looks for vulnerabilities in live systems, whereas breach intelligence touches no system at all.

// 05

Legality and GDPR

Leaked data includes personal data such as emails and passwords, so processing it falls under GDPR, even though it is data that has already leaked into public or onto the dark web. The fact that it is available doesn’t in itself mean it may be handled in any way you like.

This entry doesn’t judge what is legal in your case, and it isn’t legal advice. Assessing a specific processing operation belongs to your data protection officer or your lawyer. The factual position is only this: breach intelligence works with data that has already leaked, not with data obtained by breaking in.

// 06

Frequently asked questions

The monitoring and evaluation of data that has already leaked, meaning emails, passwords, and company details that turned up in leak databases or on the dark web. The goal is to find out which of a company’s credentials are publicly available before someone abuses them. Nothing gets broken into. What has already leaked is simply aggregated.

From leaks that have already happened: from public breach corpora, from leak databases circulating around the internet, from dark web forums where access is resold, and from bulk lists of email and password pairs. All of it has already leaked from a third party; breach intelligence only collects it in one place and compares it against the list of your addresses.

It works with data that has already leaked into public or onto the dark web, not with data obtained by breaking in. Because that data includes personal data, processing it falls under GDPR. Whether a specific processing operation is in order is for your data protection officer or lawyer to judge, not for this text. It isn’t legal advice, only a description of what breach intelligence works with.

OSINT assembles a picture of a target from publicly available information, from social networks to registers. Breach intelligence looks more narrowly, only at credentials that have already leaked. Put another way, OSINT is reconnaissance of public sources and breach intelligence is monitoring of specific leaks. Both work with what is already out there, but each with a different kind of it.

Related pages

Updated September 5, 2026.

// NEXT STEP

Find out whether your credentials are sitting in leaks that already happened

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.