Check for leaked passwords
Free breach-lookup services tell you which of your company addresses appear in known password dumps. Anything that shows up needs changing today.
Why this matters
Stolen and reused credentials are the most common cause behind the alerts issued this year. When a password from one site turns up in a dump, attackers try it everywhere else the same person works — which is how an unrelated breach becomes your breach.
The lookup takes minutes and needs no software or budget. You enter a company email address and see which breaches it appears in. Everything it returns is already public; you are only finding out what an attacker can find out too.
Checking email addresses one at a time answers the question for today. Domain monitoring answers it continuously: register your company domain once — the part after the @ in your staff email addresses, such as yourcompany.com — and you are notified whenever any address on it appears in a new breach. It is worth setting up once you have more staff than you want to check by hand. Notifications are free; listing exactly which addresses were caught needs a paid subscription above a small number. Setup is a one-off job for whoever manages your DNS or website.
What to do with the results
- Check the shared accounts first: billing, delivery portals, vendor logins. These are the passwords most likely to be reused and least likely to have been changed.
- Change the password on any account that appears in a breach, and change it anywhere else the same password was used.
- Turn on MFA on those accounts at the same time — a stolen password can be less effective when a 2nd factor is required.
- Subscribe to domain monitoring. Services such as haveibeenpwned.com offer free monitoring for low volume.
If this one helped, try another.
Consider these suggestions for what to do next. They either address the same gaps, or are logical next steps.