Monitoring for your domain's credentials appearing in breach and leak data, with a defined response — rotation, session invalidation and MFA verification.
What it is
Monitoring for your organisation’s email addresses appearing in breach and leak datasets — credential dumps from breached services, combination lists traded on criminal forums, paste sites — with an alert when one shows up.
The name oversells the mechanism. This is automated matching against collected datasets, not an analyst infiltrating forums on your behalf. That is fine; the value is in the detection and the response, not the theatre.
Why your credentials are in there
Almost always because something else was breached.
Staff register for things with their work email — a supplier portal, an industry event, an online retailer, a software trial. When one of those services is breached, the dataset includes that email address and, depending on how badly the service stored it, the password used.
If that password was also used for Microsoft 365, you have a live exposure that originated entirely outside your control. This is the reuse problem, and it is the specific risk monitoring exists to catch. You cannot stop staff registering for things. You can find out when one of those registrations turns into a liability.
The honest sizing of this control
Dark web monitoring is frequently sold as a flagship security product with dramatic branding. It does not deserve that position, and we would rather say so.
It detects one pathway. It does not prevent anything. It tells you a password is exposed; it does not stop that password working.
The control that stops the password working is multi-factor authentication. If you have MFA properly enforced, an exposed credential is a nuisance requiring rotation rather than an incident. If you do not, monitoring is telling you about a door that is standing open.
Given a choice between the two, take MFA every time. Monitoring is a useful, cheap addition once the substantial controls are in place, which is why we include it in managed security rather than selling it separately.
What we do with a finding
An alert is not a response. Each finding triggers a defined sequence:
- Rotate the password on the affected account.
- Invalidate active sessions, because a rotation alone does not evict someone already signed in.
- Confirm MFA is enrolled and enforced for that account, since exposures frequently surface accounts that were exempted years ago.
- Review recent sign-in activity for unfamiliar locations or devices.
- Where the account is finance or executive, treat it at higher severity and check for mailbox rule changes.
The initial scan almost always returns historical findings, sometimes a lot of them. Working through that backlog is part of onboarding rather than something we leave sitting in a dashboard.
What nobody can do
Remove your data from circulation. Once credentials are out, they are copied across datasets indefinitely and there is no retraction mechanism. Any service advertising removal is selling a fiction.
The only real response is to make the exposed credential worthless.