Exposed Credentials Risk Vector

The Exposed Credentials risk vector looks at verified breaches to indicate if the employees of a company had their information publicly disclosed and posted online as a result of a successful cyber attack on their company’s third parties. Use this risk vector to identify breached sites and the types of information that were exposed (disclosed attributes).

See data collection methods or the criteria for classifying data as Exposed Credentials.

Risks

Exposure can be damaging to a company’s systems and reputation. Attackers may gain access to user accounts by reusing credentials from a breach at an unrelated company and trying them on an organization’s web login page. If an employee reuses their company username and password on a non-company website and those credentials are disclosed (and the passwords are visible or guessed correctly), an attacker could potentially gain access to that employee’s corporate account.

Grading

This is an informational risk vector and does not affect security ratings.

Concept Behavior
Lifetime Duration: Not applicable.

Insufficient Data

A default risk vector grade is assigned.

Default: Not applicable.
Weight Percentage (out of 2.5% in User Behavior): Not applicable.

Remediation

Review Exposed Credential data.

  • Use Exposed Credentials as an opportunity to educate other teams and to create or re-evaluate policies on information reuse, especially requirements concerning password reuse and complexity.
  • Consider using 2-factor authentication as part of your organization’s user account security strategy.

Finding Behavior

Concept Behavior

Rescan

The Bitsight platform regularly checks for new observations. Bitsight findings are updated as these observations change, e.g., newly observed Diligence findings or an existing finding was remediated.

Automated Scan Duration: Daily

User-Requested Rescan Duration: Not Applicable

Remediated Not applicable.

Exposed Credentials Data Considerations

When classifying observations as Exposed Credential data, discovered email domains are matched with email domains owned by Bitsight customers. However, many websites do not actually validate email addresses, which makes it difficult to assert that certain exposed records are associated with company employees.

  • March 25, 2024: “No findings/low findings” changed to “insufficient data.”
  • February 12, 2024: Corrected Grading and Finding Behavior sections.
  • August 17, 2023: New Grading & Finding Behavior sections.
Was this article helpful?
33 out of 52 found this helpful

Comments

0 comments

Please sign in to leave a comment.