SECURITY - EXPOSURE CHECK AGAINST PUBLIC DATA BREACHES

Have your work credentials
already leaked elsewhere?

Data breaches regularly hit third-party services - professional networks, forums, SaaS vendors - with no connection whatsoever to your own information system. If an employee's professional address appears there alongside a password still reused today, the door is open. SYAGA Leak-Express checks your exposure using recognized public sources and supports you through remediation.

33
GDPR article (notifying the authority)
34
GDPR article (informing individuals)
72
Hours: indicative notification window (art. 33.1)
0
Real password ever requested for the check

The risk

A breach at a third party can become your problem, even though your own information system was never touched

Third-party data breaches are frequent and outside your control

A third-party service used by your employees (professional network, SaaS tool, forum) can be compromised without your own information system ever being at fault. The credentials stored there end up circulating publicly.

🔑

Password reuse turns a third-party breach into an entry point into your own systems

When a password exposed elsewhere is reused on a professional account (mailbox, VPN, remote access), the attacker only has to try it. This is one of the most well-documented compromise vectors.

🔍

Without a check, exposure stays invisible until the incident happens

A professional address exposed in an old breach can remain invisible for years, until it serves as the entry point for a credential-stuffing attack or a targeted phishing campaign.

🛡

Checking is never the same as attacking

An exposure check never means testing your actual passwords against your live services: it compares your addresses against breach data already made public, without ever attempting to log in on your behalf.

The method: Leak-Express

A check carried out by our auditors, not an automated self-service scan

1
Scoping

Defining what gets checked

You provide the domains and professional addresses to check (key accounts, management, IT). No other data is required: we never ask for a real password.

2
Check

Cross-referencing against public breach databases

Each address is checked against data breaches already made public, using recognized reference services such as Have I Been Pwned, complemented by manual OSINT research across relevant open sources.

3
Qualification

Analysis of every exposure found

For each exposure identified: which third-party service caused the breach, when it happened, what kind of data is involved (email only, password, other data), and the criticality level for your organization.

4
Report and remediation

A prioritized action plan

Concrete, prioritized recommendations: rotating the credentials concerned, enabling MFA, targeted awareness for exposed employees, and points to flag to your DPO where the context warrants it.

5
Re-check (optional)

Exposure is never a one-time state

New breaches are made public continuously, by third parties entirely outside your organization. A periodic re-check can be set up on quote, at whatever cadence suits your organization.

What you receive

A qualified, sourced report, honest about what still needs validation by your DPO or CISO

📝

Exposure check report

The list of addresses checked and, for each one, the known public breaches it appears in, if any.

  • Sources consulted, listed
  • Date of each breach identified
  • Type of data involved (email/password/other)
  • Addresses with no known exposure also listed
📊

Per-exposure qualification sheet

Each raw result is analyzed, not just copied over.

  • Origin and context of the third-party breach
  • Estimated criticality level
  • Password-reuse risk assessed
  • Associated recommendation

Prioritized remediation plan

Concrete actions, ranked by urgency, not a list of good intentions.

  • Rotation of the credentials concerned
  • MFA activation on exposed accounts
  • Targeted employee awareness
  • Actions ranked by urgency
🚩

Points to flag to your DPO

The report helps qualify the situation, without ever deciding on your behalf.

  • GDPR art. 33/34 context recalled
  • Help qualifying whether it is a breach of your own systems
  • No legal conclusion imposed
  • To be validated by your DPO or your legal counsel
🔗

Sources and traceability

Every claim is sourced, never stated from memory.

  • Public databases consulted, cited (e.g. Have I Been Pwned)
  • Documented OSINT method
  • No attempt to log into your accounts
  • No data used beyond what you provided
📄

Editable document

Delivered in an editable format, reusable by your team.

  • Ready to share with your DPO or CISO
  • Reusable for a periodic re-check
  • Same structure for every check
  • No fixed formatting imposed

References used

A method built on legal texts and recognized public sources, not on in-house interpretations

33

GDPR - Article 33

Notifying a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.

34

GDPR - Article 34

Communicating the breach to the individuals concerned when it is likely to result in a high risk to their rights and freedoms.

AN

ANSSI guide - Basic IT hygiene

ANSSI's IT hygiene measures (authentication, account management, awareness) structure the remediation recommendations in the report.

OS

Public OSINT sources

The check relies on breach data already made public, including Have I Been Pwned, a widely used reference service - never on unauthorized access to your accounts.

A tailored check, no hidden price

Scope depends on the number of addresses and domains to check. A quote is established after a first conversation.

One-off check

An initial control of your exposure

On quote
based on the number of addresses to check
  • Checking the addresses provided
  • Cross-referencing against public breach databases
  • Exposure check report
  • List of exposures found, if any
Request a quote

Periodic monitoring

Several checks over time

On quote
based on the desired frequency
  • Everything in Check + remediation +
  • Re-check at an agreed schedule
  • Tracking how exposure evolves
  • Shared methodological framework
Request a quote

Exposure is never a final state

New data breaches are made public continuously, by third parties entirely outside your organization. A check performed today guarantees nothing for tomorrow: a periodic re-check is offered on quote, at whatever cadence suits you.

Frequently asked questions

What exactly is a data breach?
It is a disclosure of data (often email/password pairs) that happened at a third-party service - a professional network, a forum, a SaaS vendor - following a security incident at that third party, with no direct link to your own information system. This data then circulates publicly and can be cross-referenced against public reference databases.
Does this mean my company has been hacked?
Not necessarily. A found exposure means a professional address appears in a breach that happened at a third party. It only becomes a risk for your organization if the associated password (or a similar one) is still used on one of your professional accounts. Our report helps make that distinction, without ever asserting it on your behalf.
Will you test my actual passwords?
No, never. The check cross-references your professional addresses against data breaches already made public. We never attempt to log into your accounts or guess your current passwords at any point: that would be unauthorized access, which we do not practice.
If an exposure is found, do I have to notify the data protection authority?
Not automatically. The notification obligation (GDPR, art. 33) concerns a personal data breach occurring within your own processing systems. An exposure found in a third-party breach only triggers that obligation if it has actually led to a compromise of your own systems. Our report documents the elements your DPO or legal counsel needs to qualify the situation.
Is this a self-service automated tool?
Not today: Leak-Express is a service carried out by our auditors, not a self-service tool. We rely on recognized public databases (including Have I Been Pwned) plus complementary manual analysis, to qualify every result instead of handing you a raw list.
How long does a check take?
It depends on the number of addresses and domains to check, and will be specified in the quote established after our first conversation about your scope.
Does this replace legal advice or a full security audit?
No. Leak-Express is a support tool that checks an exposure and documents a remediation path; it does not constitute legal advice and does not replace a full security audit of your information system. Points related to a possible GDPR notification obligation must be validated by your DPO or your legal counsel.
Why go through SYAGA?
SYAGA CONSULTING has been carrying out information system security audits since 2009 (EURL founded on 08/12/2009). This exposure check follows the same methodological rigor as our other audit services, with one strict rule: never unauthorized access, never a real password requested.

Ready to check your exposure?

Tell us the scope (domains, key addresses), and we will get back to you with a custom quote.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu Review the method