How is the Exposed Credentials Risk Vector Observed?

Exposed Credential findings are identified by aggregated breached site data. The data is collected from public sources. Email addresses belonging to a company are matched to the information in the breached site database.

To preserve business confidence and trust, we do not test that exposed credentials (such as using a username and password that were disclosed from a breached site) are valid.

  • February 8, 2021: Published.
Was this article helpful?
4 out of 5 found this helpful

Comments

0 comments

Please sign in to leave a comment.