Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
By problem · Staff in breach records

See which of your addresses are in breach records

An address at your firm lands in breach records when a service it was used with loses its user list. If the password that went with it still opens something, a stranger can sign in as you. We read from outside which of your shared addresses are listed, and from which breach.

Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before your assessment is released.

Read-only, from outsideNothing tested or logged intoReviewed by a person
What we check for thisRead-only
Shared addresses
info@, admin@ and contact@ at your domain, in monitored breach databases
Which breach
The breach that listed each address, and when
Named staff
Only in the paid assessment, from a list you give us and authorise
Passwords
Never tried. We do not test whether a listed password still works
Reviewed by a person before release. Every finding carries a check anyone can run.
01 · What we check

What a listed address means, and what we read.

A reused password is still one of the first ways into a firm, and a list of real addresses is where the attempt starts.

01
Shared addresses

Addresses such as info@ and admin@ are read by several people, printed on your website and often the sign-in for your domain, your website or a payments portal. We check whether each appears in monitored breach databases.

02
The breach behind it

For each listed address, the breach that listed it and its date, so your IT provider knows which password to change and where it was used.

03
Named staff, with your say-so

We do not look up your people on the free reading. In the paid assessment you give us the staff addresses to check, and we check only those.

04
What to change

Change the password wherever that address is a sign-in, to one used nowhere else, and turn on two-step sign-in for it. On its own, two-step sign-in defeats a reused password.

02 · What we measured

Measured on 30 September 2026.

2 in 10
Professional firms have a shared address such as info@ in monitored breach databases.

Measured across the firms we have assessed in Canada and the United States, not a national census. The method is in the study.

03 · What we read

The outside view, in plain words.

Monitored breach databases
Published breach lists, searched for the shared addresses at your domain, with the name and date of each breach that listed one.
Unanswered lookups
If a lookup goes unanswered, we never show it as a clean result. A check that did not run is not a clean bill of health.
What it cannot see
Whether a listed password still works, or where your staff reused it. We log into nothing and try no password.
How we are different

Next to the people you already work with.

Your IT provider

Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.

A penetration test

Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.

Your insurer's scan

Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.

For your firm

See which of your addresses are listed, before someone signs in with one.

The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.

Check my firm