How to Check for a Data Breach
Where breach data actually surfaces, what a result means, and the response that matters for each kind.
- john@smithdental.com
- sarah@smithdental.com
- maria@smithdental.com
- No Login
- No Software
- No Network Access
- Public Records Only
We confirm an account appears in breach data. We never test a credential, and we never publish one back to you.
What You Are Actually Checking For
There is no central registry of breaches to search. Checking for a breach means looking at the places breached information surfaces afterward, and there are three that matter for a business.
Credential corpora aggregated from past breaches. Infostealer logs from machines currently infected with malware that copies saved logins. And public exposure, where information is reachable because of a configuration error rather than any breach at all.
What a Breach Record Contains
Breach corpora list the address, the source, and often the password itself. We show that a record exists and redact the credential, because publishing it would hand it to the next person who looks.
The Three Places to Look
Breach Corpora
Aggregated datasets from past breaches of unrelated services. An address at your domain appearing here is common and usually old.
Infostealer Logs
Data from machines infected with credential-stealing malware.
Your Own Exposed Surface
A database, backup, or file store reachable from the internet because of a setting rather than an intrusion.
How to Tell Whether It Is Old or Live
Age is the question that determines urgency. An address in a corpus from a breach several years ago, where the password has since changed, is a historical fact rather than an open risk.
The signals that suggest something live are a recent corpus date, a credential matching a system still in use, and any appearance in infostealer data, which by nature reflects an infection rather than an old leak.
Where the date is unknown, treat it as live. Resetting a password that did not need it costs nothing meaningful, and the reverse mistake is expensive.
What to Do When You Find Something
Deal With the Machine First, If There Is One
For infostealer results, the infected computer has to be cleaned before anything else. Changing passwords while a stealer is running simply hands over the new ones.
Reset the Affected Credentials
Every account using that password, not only the one named. Reuse is what turns a single old breach into a current problem.
Turn On Two-Step Login
This is the control that makes a stolen password insufficient on its own. It is the highest-value change available and it is free on every major platform.
Check What the Account Could Reach
An exposed account is a route to whatever it had access to. Email, files, the practice management system. The reset closes the door; the review tells you whether anyone walked through it.
Write Down What You Found and Did
If a reportable breach is ever established, the record of when you knew and what you did is the difference between a manageable situation and a much worse one.
What You Do With the Answer
Confirming exposure is the easy half. The order to fix it in is the half that matters.
Common Questions
Usually not. It most often means a service one of your staff used was breached, and their work address was in that service's database. Your systems may be untouched. It matters because of password reuse rather than because of the original breach.
Notification obligations depend on what data was involved and which rules apply to your business. An address appearing in a third party's breach is generally not your notifiable event. Actual unauthorized access to your own records usually is, and that is a question for a lawyer rather than a scanner.
New corpora publish without warning, so a single check has a short shelf life. Monthly is a reasonable floor for a small business, and continuous monitoring is the honest answer if the data matters.
Blindspot is not a penetration test and does not attempt to use anything it finds. Every check reads public records and publicly available corpora only. Nothing is logged into, no password is tested, and no network is touched. Blindspot never displays, stores, or transmits a recovered credential in whole or in part. Results are reported as counts and dates. That limit is deliberate and is not a feature that can be unlocked.
Check Your Domain
Counts and dates, never a credential. Free, about thirty seconds.
We only read public records. We never touch your computers and we never ask for a password.
Keep Reading
Three places this leads next, depending on what you want to do about it.
- ExplainerDark Web Scanning for BusinessA dark web scan checks whether addresses at your domain appear in breach and credential corpora. Here is what those scans actually search, what the results mean, and what to do when your business appears.
- Deep DiveSecurity Posture ManagementSecurity posture is the measurable state of your defenses at a point in time. Here is what it means for a business with no security team, how it is measured from the outside, and how to improve it without buying enterprise software.
- The ScanWhat Your Result Will Look LikeWhat you get from a free Blindspot scan: a grade, a prioritized list of findings, and the evidence behind each one. See what your result will look like before you run it.