Skip to content

What Is Leaks? Understanding a Subject’s Breach Exposure

temenigruProduct

Breach data is the part of someone's digital footprint they did not choose. An address that appears in a decade of dumps, a password reused across services, a corporate domain showing up repeatedly: each is a fact about exposure, and in security and due-diligence work, exposure is the question.

Leaks searches breached credential material and dark web mentions tied to the subject under review.

What exposure tells an investigation

For corporate security: which of the organisation's identities are already circulating, and therefore where account takeover is cheapest for an attacker.

For due diligence: whether a counterparty's operational hygiene matches what they claim in a questionnaire.

For investigations: corroboration. An identifier appearing across unrelated breaches is a thread between accounts that otherwise look separate.

Findings, not verdicts

Breach material is messy. Records get merged, addresses are reused, and a hit against a common address is often not the person in your case. Leaks results enter the case like any other evidence — as claims with sources, reviewed before they are accepted. See accepted and rejected evidence and the homonym problem.

Used within the law, and only for the case

This capability exists to assess the exposure of a subject under authorised review: your own organisation, a counterparty within a mandate, or a subject inside a lawful investigation. It is not a lookup service for arbitrary people, and it is governed by the same scope, legal basis and retention rules as the rest of the case file.

Material of this kind is sensitive. Treating it as ordinary case evidence — admitted deliberately, retained for a reason, removed when the case ends — is the difference between risk analysis and liability.

Where the results go

Exposure findings connect to the entities they belong to in Engramite Graph and, if admitted, appear in the report with their provenance.

Frequently asked questions

Is this a "have I been pwned" lookup? No. It is an investigative capability used inside an authorised case, with review and retention.

Do results prove an account belongs to the subject? No. They are evidence to be corroborated, especially where the identifier is common.

Is it enabled by default? Capabilities are selected per case — see Plugins.


Read next: Campaigns or Engramite Graph.