Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Credential exposure
Reference · Pattern

Credentials in monitored breach databases reused on production login

Severity CriticalKind Credential exposureEffort to fix ModerateUpdated 29 Sep 2026By LeakTrace
Definition

Employee credentials appearing in monitored breach databases are still active on the corporate SSO or VPN, giving attackers a direct password-spray path.

What it is

When a third-party service is breached and credentials are dumped to a paste site or dark-web marketplace, those credentials get indexed by public breach databases within hours. If an employee reused the same password on the corporate SSO, VPN, or Microsoft 365 tenant, the attacker now has a working set of credentials without any need for phishing.

Why it matters

Password-spray attacks against corporate identity providers use exactly this input: a list of valid usernames (harvested from the target's domain via public-record scrapers) combined with a list of passwords that have appeared in prior breaches. The attacker never triggers a lockout because they test one password at a time across many accounts, and one working credential is enough to open a session.

How anyone can check it

Check each staff address in a public breach-notification service, then confirm those passwords were changed.

Remediation direction

Daily credential-exposure monitoring against the workforce's corporate email domain, combined with MFA enforcement on every identity provider and immediate password rotation on exposed accounts. Managers should be alerted when a direct report's credential surfaces so the rotation happens the same day, not on the next quarterly review.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →