
EXPOSED CREDENTIALS
Accounts already in circulation
Corporate email addresses and usernames, the websites and login URLs they were captured with, password exposure indicators, exposure timestamps, and the corporate and third-party services involved.

INFOSTEALER MALWARE
The device behind the leak
Malware family or infection indicators, device identifiers and hostnames, operating system metadata, infection and collection timestamps, the accounts tied to the device, and network or location metadata where available.

BROWSER & SESSION
Sessions that outlive a password reset
Cookie exposure indicators, potential authentication session exposure, the websites and services involved, and browser metadata. An exposure record alone does not prove a session is reusable or that access occurred.

CORPORATE APPLICATIONS
VPNs, cloud consoles, admin portals
Internal and external application login URLs, VPN and remote access account indicators, cloud service accounts, business and administrative application accounts, and third-party service credentials.

EMAIL ACCOUNTS
One person's entire exposure
Addresses found in credential exposure records, the accounts and services tied to them, malware-related indicators, exposure dates and source information, and related compromised device details where available.

PUBLIC BREACH RECORDS
Incidents already on the record
Affected addresses and their incidents, breach names and descriptions, reported dates, categories of compromised information, the affected services, and exposure and publication dates.