// 13 · DATA BREACH AND LEAKED CREDENTIAL MONITORING
Data breach and leaked credential monitoring
Data breach monitoring continuously checks whether your company email addresses, domains, and credentials have turned up in data that has already leaked somewhere. It is breach intelligence, that is, work with data from breaches that have already happened, not an intrusion into anything. We don’t crack or bypass anything: we aggregate what already sits in public or on the dark web and watch for your people in it. A leak can appear at any time, not just on the day you have a test done.
// 01
What we monitor
We watch two things: your company email addresses and your domains. For addresses we check whether a specific address, password included, has appeared in a leak; for domains, whether accounts registered under your domain are sitting somewhere. We compare them against databases of already leaked credentials, which are built from past breaches of third-party services.
The problem isn’t that something leaked from you directly. An employee uses a company email to register with an outside service, that service gets breached, and a password that is the same as the one for work is suddenly out. A leak like that shows no sign on your side until someone abuses it. That is exactly the gap monitoring closes.
Besides open breach databases we also watch dark web sources and leak forums where leaked data is resold. Dark web monitoring means we watch the more closed places an ordinary search engine can’t reach, not that we do anything active there. Here too we only read what has already leaked.
// 02
One-time check versus continuous monitoring
The difference is simple: the bonus check is a photo of one day; paid monitoring is the film. With every engagement we run a one-time leak check free of charge. It tells you what is out there as of the day we run it. It’s a useful snapshot, but it only holds for that moment.
A leak, though, appears whenever a service someone from the company had an account with gets breached. That can be a week after the test, in three months, in a year. A one-time check from last quarter knows nothing about it. Only continuous monitoring catches it, because it keeps checking and alerts you the moment the data appears, not at the next test.
So the paid service isn’t a pricier version of the bonus; it is a different thing. The bonus answers the question of what has leaked so far. The subscription answers what will leak next, and that is the question that matters: an attacker uses a freshly leaked password right away, not once you happen to remember it.
// 03
What happens when a leak appears
As soon as your data appears in a new leak, you get an alert. Not a monthly report nobody reads, but a notification the moment the finding arises, because with a leaked password what counts is how fast you invalidate it before the attacker uses it.
With the alert we tell you what to do about it: which accounts to reset, where to enforce multi-factor authentication (MFA), and whether active sessions need revoking so a logged-in attacker gets kicked out. When a finding is larger or unclear, we go through the response together on a call; that is one of the topics of a consultation on what to do when your data leaks.
// 04
Where the leaked data comes from
We take data from three kinds of sources: public breach corpora that aggregate large past breaches, leak databases circulating on the internet, and dark web forums where access is resold. They have one thing in common: everything in them has already leaked; we only gather it in one place and compare it with your list.
It is the same principle as the public services for checking leaked passwords, only focused on your whole company, not one address. We don’t crack anything, we don’t break in anywhere, and we don’t obtain any data ourselves from live systems. We work exclusively with what is already out.
The legal assessment of this work is for your data protection officer or your lawyer; we don’t do it. The factual situation, though, is simple: the data we work with has already leaked, in public or on the dark web, and monitoring exists so that you react to it before someone else does.
// 05
A leak check included with every engagement
We add a one-time leak check free of charge to every engagement: a pentest, a phishing simulation, or a consultation. When we hand over the results, we also tell you whether any of your credentials are out there as of the day of the check.
It’s a meaningful start, because a leaked password opens a way in quietly: a login with a valid account raises no alarm. How leaked passwords are then used against people is what a phishing simulation checks. If you want to know about a leak afterward too, not just as of the day of the engagement, you move to the continuous subscription.
// 06
What it costs
Monitoring is a continuous service, so it is paid by subscription, monthly or annually, not as a one-time engagement in person-days. The price follows the scope, that is, the number of domains and email addresses we watch. The more addresses and domains, the larger the scope.
The one-time check with every engagement stays free; the subscription pays for the monitoring to keep running. The pricing page explains why monitoring is priced differently from the other services. You get an exact price based on your list of domains and addresses, not a flat fee for everyone.
// 07
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 08
Frequently asked questions
// NEXT STEP
We’ll go over the scope together.
Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.