Skip to content
New breaches tracked daily · via RecentBreachesFor Business

The way into your company is one of your people.

They pick your company, then they pick a person — often the one who moves money, resets things, or holds a calendar and a signature. Frequently that is you. Then they stop looking at your company altogether, because what opens the door is that person’s private life, and most of it is published rather than stolen. We watch the leaked-data corpus for your company’s addresses and tell you the moment one of your people turns up in it.

Employee exposure monitoring from $1,000/month, quoted per domain · we check 13.1B+ leaked records · no software to install, nothing to connect to your systems.

A heavy door standing ajar, with light falling through the gap onto the floor.

Nobody has to break in. They log in as one of your people.

This is the route that does not look like an attack while it is happening. Most of it runs through your staff’s private lives, which is the part no security tool you own is watching.

  1. They stop looking at your company

    This is the turn, and it is the step that gets missed. Your domain is left alone entirely. The work moves to the person — a personal address, accounts opened years before they worked for you, and the look-up sites that publish where they live. Almost none of it was stolen. It is on sale, and it is cheap.

  2. They assemble the person

    Home address, phone number, relatives’ names, the town they grew up in. A password from an old breach, and the pattern behind it — a season, a year, a punctuation mark on the end. The answers to your own password-reset questions are, for most people, published facts. Most often the person worth assembling is whoever moves money, resets things, or holds a calendar and a signature. Frequently that is you.

  3. They become the person

    Two doors, and they only need one. Either the same password still works somewhere it should not, or they telephone your help desk, pass your verification using published details, and your team resets the second factor for them — correctly, politely, exactly according to the procedure. What arrives next is a real name, a real credential and a real session in normal working hours. Nothing was forced, so nothing raises an alarm.

The middle step is the one on sale, and it is the one almost nobody watches. Most of this category monitors the password and treats the rest as the employee’s private business. It is the private business that makes the phone call work.

And it does not stop at one person. The same afternoon’s work runs again under the next name on the list, which is why this is bought for a company rather than for a person.

What we look at, and what we hand you.

You give us your domain. Not a login, not access to anything, not an agent on a laptop — just the domain your staff receive mail at.

Every address at your domain that has leaked
We search 13.1B+ leaked records for anything ending in your company’s domain, and count the distinct people behind it.
Which breach it came from, and when
Named source and date for each one, so your team can tell an old incident that has been dealt with from one nobody has seen before.
How many came with a password
This is the number that matters. An address on a mailing list is not the same event as an address sitting beside a reusable password, and we report the two separately. Most tools in this category add them together and quote you the larger figure.
New exposures, as they appear
The corpus grows. A domain that is clean today is not clean permanently, so the check runs again and you hear what is new rather than being re-sent what you have already read.

The report is the thing you buy.

An attack-surface map drawn from your own people: what somebody assembling an attack on your company can already see, where they got it, and which parts of it still open something.

  1. Which of your people are exposed, and in what

    Named addresses at your domain, the breach each came from, and the date. The list your IT team works from, not a dashboard number.

  2. Which exposures include a password

    Separated from the rest, because it is the part that opens a door. These are the accounts to reset first, and the ones to check against your own password store for reuse — a check you run internally, on your own systems, which is the correct and lawful way to answer “does this still work here?”

  3. What links back to the company

    Where a personal exposure carries something that ties a person to your organization — the work address, a role, a corporate identifier.

    So you can see which leaks are that employee’s private matter, and which are a route to you.

  4. What is new since last time

    You get the delta, not the same list re-sent, so the report stays something a person acts on rather than something that gets filed.

Prevention here is not us reaching into your systems. It is handing your team a short, specific, sourced list of accounts to reset and reuse to check — then telling them the moment that list changes.

What it costs.

Priced on how many domains you need watched and how many people sit behind them. None of it is bought from a page — every route ends in a conversation and a written quote.

Employee exposure monitoring

from $1,000/month

We search 13.1B+ leaked records for your company’s domain, tell you which of your people are already exposed and how many of those records carry a password rather than just an address — then keep checking and tell you what is new.

Quoted per domain. Larger groups, subsidiaries and acquired brands are scoped on the call.

Engagements start with a scoping call and a setup period: we agree the domains, the recipients and the reporting cadence, run the first exposure report against them, and stand the monitoring up on that. It is a contracted service rather than a self-serve product, which is why there is no price to click and no trial to start.

Get your company checked →

Your executives and their families

$249/yr

A different problem, and it is worth keeping the two apart. This one is about the person rather than the company: the home address, the relatives and the phone number that 28 look-up sites publish about your named people. We file to take those listings down as their authorized agent, and file again when they return.

One household covers up to 5 people. Teams are quoted per person after a call.

Executive and family protection →

Watching other companies rather than your own staff — suppliers, an acquisition target, a portfolio — is a different question with its own product: GalaxyWarden Signals.

Buying for yourself rather than for a company? The consumer prices — the free scan, the full report and Protection — are on the pricing page.

What we will not do, and will not claim.

Four things, stated the same way in the engagement as they are on this page.

  • We never test a password against your systems

    Not once, not with your permission, not as a demonstration. Trying a leaked credential against a live login is unauthorised access, and no customer consent makes that our business. We tell you the credential is out there. Whether it still opens anything is yours to check.

  • We never show you or store the password

    We report that one exists, and which breach it came from. A monitoring service whose own database becomes a credential dump is a liability rather than a service, and “here is the actual password so you believe us” is exactly how that happens.

  • A leaked staff address does not mean you were breached

    It almost always means a third party was. We will not tell you your company has been breached on that evidence, and you should be wary of a supplier who does — it is a serious claim about your business and it belongs on a filing or a disclosure, not on an inference.

  • We cannot promise the list is complete

    No one can see every dump that exists. We can tell you what is in the corpus we hold and where each record came from. A supplier who tells you they see everything is describing an ambition.

Tell us who you need to protect.

A senior lead replies within one business day with who we would cover, what we would file, and what it costs per person. No queue, no sales sequence.

Handled under NDA on request.