What it is
When a third-party service is breached and credentials are dumped to a paste site or dark-web marketplace, those credentials get indexed by public breach databases within hours. If an employee reused the same password on the corporate SSO, VPN, or Microsoft 365 tenant, the attacker now has a working set of credentials without any need for phishing.
Why it matters
Password-spray attacks against corporate identity providers use exactly this input: a list of valid usernames (harvested from the target's domain via public-record scrapers) combined with a list of passwords that have appeared in prior breaches. The attacker never triggers a lockout because they test one password at a time across many accounts, and one working credential is enough to open a session.
How anyone can check it
Check each staff address in a public breach-notification service, then confirm those passwords were changed.
Remediation direction
Daily credential-exposure monitoring against the workforce's corporate email domain, combined with MFA enforcement on every identity provider and immediate password rotation on exposed accounts. Managers should be alerted when a direct report's credential surfaces so the rotation happens the same day, not on the next quarterly review.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.