High-impact

Check for leaked passwords

Free breach-lookup services tell you which of your company addresses appear in known password dumps. Anything that shows up needs changing today.

Run the lookup haveibeenpwned.com A free breach lookup service. No account needed. No cost. Back to the Toolkit →

Why this matters

Stolen and reused credentials are the most common cause behind the alerts issued this year. When a password from one site turns up in a dump, attackers try it everywhere else the same person works — which is how an unrelated breach becomes your breach.

The lookup takes minutes and needs no software or budget. You enter a company email address and see which breaches it appears in. Everything it returns is already public; you are only finding out what an attacker can find out too.

Checking email addresses one at a time answers the question for today. Domain monitoring answers it continuously: register your company domain once — the part after the @ in your staff email addresses, such as yourcompany.com — and you are notified whenever any address on it appears in a new breach. It is worth setting up once you have more staff than you want to check by hand. Notifications are free; listing exactly which addresses were caught needs a paid subscription above a small number. Setup is a one-off job for whoever manages your DNS or website.

What to do with the results

  • Check the shared accounts first: billing, delivery portals, vendor logins. These are the passwords most likely to be reused and least likely to have been changed.
  • Change the password on any account that appears in a breach, and change it anywhere else the same password was used.
  • Turn on MFA on those accounts at the same time — a stolen password can be less effective when a 2nd factor is required.
  • Subscribe to domain monitoring. Services such as haveibeenpwned.com offer free monitoring for low volume.