Email exposure checks
Every address on your registered domains checked against known breach data, including the dormant, shared and departed-staff accounts that rarely appear on anyone's asset list and often still have live access.
Third-party breaches leak your employees' work email addresses and passwords into circulation, and password reuse turns someone else's incident into your incident. We check your domains against breach corpora and criminal marketplace data, tell you exactly what is exposed, and help you shut the door.
A dark web exposure assessment searches for your organisation's footprint in places you cannot check yourself: aggregated breach corpora from previous third-party incidents, credential dumps traded on criminal forums, combination lists compiled from many breaches at once, and marketplace listings advertising access to corporate accounts.
We search on your registered domains rather than on individuals, which means the assessment covers every mailbox on the domain including shared, service and legacy accounts that nobody remembers still exist. For each hit we report the email address, whether an associated password or hash was exposed, the breach it came from, the date, and what else leaked alongside it, such as phone numbers, addresses or security questions.
The assessment then answers the question that actually matters: which of these exposures still present live risk. A password leaked in a 2019 breach that was changed in 2021 is history. The same password still in use on a VPN account with no multi-factor authentication is an open door, and it is graded accordingly.
Almost every organisation has exposure, because the exposure rarely originates with them. An employee signs up to a conference platform, a hotel booking site or a professional network with their work email address. That third party is breached. The credential enters circulation, and if the employee reused the password anywhere, so has your access.
Attackers automate the rest. Credential stuffing tools test leaked pairs against corporate mail portals, VPN gateways and cloud consoles at scale. This is a cheap, quiet attack that produces no malware for your defences to detect, because from the system's point of view someone simply logged in correctly.
There is also a disclosure dimension. Under the amended PDPA, an organisation must notify the Commissioner where a personal data breach occurs, and notify affected individuals where the breach is likely to cause significant harm. Knowing what is already exposed helps you distinguish between a fresh incident and historical third-party leakage, which is a distinction you very much want to be able to make quickly and evidentially.
The output is scoped, sourced and dated. Every finding can be traced back to where it came from, so nothing in the report has to be taken on faith.
Every address on your registered domains checked against known breach data, including the dormant, shared and departed-staff accounts that rarely appear on anyone's asset list and often still have live access.
Where a password or password hash was exposed alongside an address, we report that a credential exists and characterise it, for example whether it is plaintext, a weak hash or a strong hash. We do not distribute plaintext passwords in reports; we tell you which accounts need resetting and why.
Each exposure is tied to a named source breach with its date and the categories of data involved. This context is what turns a raw list into something you can triage, because a 2016 forum breach and a 2025 cloud provider breach demand very different responses.
Beyond credentials we look for lookalike domain registrations that could be used to impersonate you, mentions of your organisation in criminal forum discussion, and exposed technical footprints such as public code repositories carrying internal keys.
Every finding is graded on whether the credential is likely still valid, how privileged the account is, whether multi-factor authentication protects it, and how recent the exposure is. You get a short list of accounts to act on today rather than a spreadsheet of thousands of rows.
Specific remediation for the exposures found, plus the structural changes that stop the same thing recurring: multi-factor authentication coverage, password manager rollout, joiner-mover-leaver hygiene and monitoring for future leaks.
This is one of the fastest assessments to run and often the one that produces immediate, concrete action within days.
Most assessments surface a handful of accounts where a still-valid credential is exposed and multi-factor authentication is not enabled. Those get fixed the same week, and that alone frequently justifies the engagement.
Domain-wide checking consistently uncovers mailboxes belonging to people who left years ago, shared accounts with a password on a sticky note, and service accounts nobody has reviewed since the system was installed.
When a credential surfaces later, having a dated baseline lets you establish whether it is historical third-party exposure or evidence of a fresh compromise. That distinction drives your notification obligations and can save an unnecessary regulator filing.
Telling staff not to reuse passwords changes little. Showing a department that eleven of its work addresses appear in breach data, with the source and date, changes behaviour immediately.
Enterprise vendor questionnaires increasingly ask whether credential exposure is monitored. A dated assessment and a remediation record is a clean answer.
Multi-factor authentication projects stall on inconvenience arguments. A report showing real exposed credentials on real accounts tends to end that debate.
A first assessment usually completes within two weeks. Continuous monitoring can then run in the background with alerts as new exposures appear.
We agree which domains and subdomains are in scope and verify that you control them, because we will not search on a domain a client cannot demonstrate ownership of. We also agree who receives findings, since exposure reports can name individuals and need handling with care.
We query your domains against breach corpora, credential dump collections and marketplace intelligence sources, and run the wider brand and infrastructure checks. Collection is entirely passive: nothing touches your systems and nothing is purchased from criminal sellers.
Raw hits are deduplicated and enriched with the source breach, its date and the data categories involved. False positives and recycled listings are stripped out here, which is the difference between a useful report and an alarming but meaningless number.
Each surviving finding is graded against account privilege, current MFA coverage, exposure age and likely credential validity. We work with your IT team to confirm which accounts are still active, because that is knowledge only you hold.
You receive the exposure report and a prioritised remediation list, and we walk through both. Immediate actions such as forced resets on high-risk accounts usually begin during that session rather than after it.
Exposure is not a one-time state. Clients typically move to periodic rechecks or continuous monitoring, which is included in our human risk management programme alongside simulation and awareness activity.
Findings are delivered through a channel you nominate and handled as sensitive material, because an exposure report is a useful document for an attacker too.
The complete inventory of exposed addresses and credentials by domain, each with its source breach, date and exposed data categories.
The accounts requiring action now, ranked by risk, with the specific action for each: forced reset, MFA enforcement, account disablement or privilege reduction.
Analysis of what the pattern of exposure tells you, including which third-party services your staff register with using work addresses and where reuse is concentrated.
Lookalike domain registrations, forum mentions and exposed technical assets, with recommended action for each.
A one-page account of the exposure position in business terms, suitable for the board or the audit committee.
The structural controls that reduce future exposure: MFA coverage targets, password manager rollout, account lifecycle hygiene and a recheck schedule.
Every organisation with a corporate email domain has some exposure. The organisations that need to know most are those where a single valid credential unlocks money or personal data.
Sectors where account takeover leads directly to fraud or a reportable data breach see the strongest case for regular assessment.
Cost scales with domain count rather than headcount, so this is one of the few enterprise-grade assessments that is genuinely affordable for a smaller organisation.
Findings are routed to the teams that can act on them, and to the functions whose exposure carries the most consequence.
Anyone can produce a list of leaked email addresses. The value is in knowing which ones still matter and what to do about them by Friday.
We treat exposure as a governance issue rather than a scare tactic. Findings are graded, sourced and dated so they can be entered on a risk register, tracked to closure and shown to an auditor, and we will tell you plainly when a finding looks alarming but carries no real residual risk.
The remediation list is ordered by what actually reduces risk fastest, and each item names a specific action against a specific account. Most clients close their highest-risk findings within a week of the debrief, because the report tells them precisely what to do rather than describing a general problem.
Our consultants have run compliance, data protection and security functions inside Malaysian organisations, not only advised on them from outside. That shows up in the advice: we know what a lean IT team can absorb in a quarter, and we know which recommendations get quietly shelved.
Scenarios use Malaysian references your staff will recognise, from DuitNow payment requests and e-invoice notices to LHDN and EPF correspondence. Reporting is framed against the obligations your regulators and auditors actually cite, including the 72-hour personal data breach notification duty introduced by the 2024 amendments to the PDPA.
Where the findings point to a password behaviour problem across the workforce, the awareness training that addresses it can be delivered as an HRD Corp claimable programme for levy-contributing employers. See HRD Corp claimable cybersecurity training.
Tell us your headcount, your industry and what triggered the interest, whether that is an audit finding, a near miss, a board question or a regulator letter. We will come back with scope, timeline and a fixed quotation. No obligation, and we will say so if you do not need us yet.