Stolen Credentials: Detection
Stolen credentials refer to user account information (typically usernames or email addresses and passwords) that have been compromised and made available in underground markets or public data dumps. These leaks often result from data breaches of various organizations and can pose significant risks when employees use the same credentials across personal and professional accounts.
How We Detect Stolen Credentials
Our process for identifying stolen credentials involves:
- Data Collection:
- We maintain access to extensive databases of leaked credentials from various sources.
- These databases are regularly updated with new leaks and breaches.
 
- Asset Identification:
- We compile a list of email domains and usernames associated with your organization.
 
- Database Scanning:
- We scan the leaked credential databases for matches with your organization's email domains and usernames.
 
- Pattern Matching:
- We look for common username patterns that might be associated with your organization but not use your official email domain.
 
- Historical Analysis:
- We check for credentials leaked in past breaches that might still be in use.
 
- Continuous Monitoring:
- Our systems continuously monitor for new leaks and breaches, providing real-time alerts for newly compromised credentials.
 
What We Look For
- Email Addresses: Corporate email addresses found in leaked databases.
- Usernames: Common username formats used by your organization.
- Passwords: Leaked passwords associated with identified emails or usernames.
- Additional PII: Other personally identifiable information that may be included in the leak.
- Breach Sources: Information about where and when the credentials were leaked.
Implications of Stolen Credentials
- Account Takeover: Attackers can potentially access corporate accounts using stolen credentials.
- Data Breaches: Compromised accounts can lead to unauthorized access to sensitive corporate data.
- Phishing Campaigns: Stolen email addresses can be targeted in sophisticated phishing attacks.
- Reputation Damage: If exploited, stolen credentials can lead to incidents that damage company reputation.
- Financial Loss: Both direct theft and remediation costs can result in significant financial impact.
- Regulatory Issues: Exposure of certain types of data can lead to compliance violations and fines.