Skip to main content

Intelligence module

What is publicly observable about your organisation, and what it actually means

Exposure intelligence attracts more overstatement than any other area of this assessment. The findings here are deliberately measured, deliberately incomplete in public, and never presented as evidence of compromise.

Intelligence provided by Intelis.

This module is presented as Identity & Breach Exposure in the report, and intelligence for it is provided by Intelis.

It exists because organisations frequently discover, at an inconvenient moment, that something about them was publicly observable and nobody had looked. A staff address appearing in a third-party breach dataset. A domain registered last month that differs from yours by one character. A document published years ago that still carries internal metadata.

None of these are necessarily problems. All of them are things you would rather know than not know, and the appropriate response depends entirely on being clear about what each one does and does not establish.

Scope

What is examined

Public indicators only. Everything reported here is observable without access to any of your systems.

Organisational email

  • Addresses published on the website itself
  • Whether role-based or individual addresses are exposed
  • Patterns that make other addresses predictable
  • Aggregate counts rather than lists

Breach association

  • Whether domain addresses appear in known third-party datasets
  • How many distinct incidents are associated
  • The approximate period involved
  • Available only to a verified domain owner

Lookalike domains

  • Registered variants resembling the primary domain
  • Character substitutions and alternative extensions
  • Whether any resolve to active content
  • Whether any publish mail routing

Impersonation signals

  • Content on other domains presenting as the organisation
  • Use of brand assets outside your control
  • Indicators consistent with a phishing target
  • Reported as observation, not as conclusion

Public documents

  • Documents published from the domain and reachable publicly
  • Whether they carry internal metadata
  • Whether any appear unintended for publication
  • Reported by character rather than by listing

Public infrastructure signals

  • Subdomains observable in public sources
  • Certificate transparency history
  • Names suggesting non-production environments
  • Withheld from public output entirely

An address at your domain appearing in somebody else's breach tells you a person used a work address to sign up to something. It does not tell you that anything of yours was touched.

Privacy

What is never displayed

This module handles information about people, which imposes obligations that go beyond what is technically available. The constraints below apply at every level, including paid engagements with verified owners.

Public output uses masking and aggregation: an address appears as j***@example.com, and findings are expressed as counts rather than lists. Detailed organisational breach review, where it is available at all, sits behind domain verification and appropriate authorised data access.

IXSEO does not hold, process or display credential material. Where a dataset contains it, that portion is outside what this service engages with entirely.

Never displayed

  • Complete employee email addresses
  • Passwords, hashes or credential material of any kind
  • Raw breach records
  • Stealer log contents
  • Individual employee findings
  • Exact internal assets or hostnames
  • Anything identifying a named individual as exposed

Example finding

A representative finding

This is an illustration of the report format rather than a result from a real assessment.

Moderate

Organisational Addresses Appear In Third-Party Breach Datasets

What we found
Three addresses at your domain are associated with two known third-party incidents, the most recent dating from within the last two years. Addresses are shown in masked form, for example j***@example.com. No indicator suggests these datasets originated from your own systems.
Why it matters
Breach association is not evidence of compromise of your infrastructure. It indicates that work addresses were used with external services that were later breached, which raises the likelihood of targeted phishing against those addresses and creates risk where passwords have been reused across services.
General direction
Treat this as a prompt to confirm that multi-factor authentication is enforced on the accounts involved and that password reuse is addressed through policy rather than assumption. There is no action required against your own infrastructure on the basis of this finding alone.
How IXSEO can help
Identity & Breach Exposure review, with intelligence provided by Intelis.

Verification and access

Reflects the volume and nature of publicly observable exposure indicators associated with the domain. It is not a measure of active compromise.

Detailed exposure findings require domain ownership verification before they can be displayed, and organisational breach review additionally requires authorised access to a source such as Have I Been Pwned. Where that access is not configured, the module reports what it can establish from public signals and states plainly what it could not check.

Domain verification confirms control of an approved domain resource. It does not automatically authorise active testing of company infrastructure.

Intelligence provided by Intelis

Frequently asked questions

Does a breach association mean we have been hacked?
No, and conflating the two causes a great deal of unnecessary alarm. It means an address at your domain appeared in a dataset from an incident at some third-party service — a forum, a supplier, a platform someone signed up to with a work address. Your systems may never have been touched. It is a signal worth knowing about, not a conclusion.
Will you show me the exposed passwords?
Never. Not in the public snapshot, not after verification, not in a paid engagement. IXSEO does not handle credential material, stealer logs or raw breach records. What can be provided to a verified owner is the shape of the exposure — how many organisational addresses, associated with how many known incidents — which is what informs a response.
Why are email addresses masked?
Because they belong to people, and publishing a list of your staff's addresses to anyone who types your domain would be a privacy failure regardless of whether each address appears somewhere already. Public output uses forms such as j***@example.com and aggregate counts.
What is a lookalike domain?
A registered domain resembling yours closely enough to be mistaken for it — a transposed letter, a different top-level domain, an added hyphen. Most are harmless: defensive registrations, expired assets, speculative holdings. Some are used for impersonation. The module reports what exists; establishing intent requires investigation.
How is this different from a dark web monitoring service?
Those services monitor continuously and alert you to new appearances. This is a point-in-time assessment forming part of a wider website review, oriented towards whether exposure indicators suggest something worth acting on. It is not a monitoring subscription and does not present itself as one.

See what is publicly observable

Public Exposure is an optional module on the free snapshot. Selecting it will show the verification notice, because the detailed findings require ownership to be demonstrated.