bf-leakwatch
Dark web monitoring

Your credentials are already up for sale. Nobody just knows it yet.

bf-leakwatch searches the dark web around the clock for credentials belonging to your company. When something turns up, you know within minutes, which account is affected, where the find came from and what to do about it.

  • Monitored around the clock
  • Hosted in the EU
  • GDPR-compliant
FindingsLive
An employee mailboxm.wagner@your-company.com · plain-text password · infostealer log 4 min ago
Supplier portal loginCombo list, 2.4 million records · password reused elsewhere 2 hrs ago
Password resetFinding from 12 Aug · confirmed by your IT team yesterday
Illustrative example, not real data.
The problem

Between the leak and the attack there are usually weeks.

Stolen credentials are rarely used straight away. They are collected, bundled into lists, traded and only then put to work. That gap is your head start, as long as someone is watching. Otherwise you learn about the leak once somebody is already inside.

Why this matters

Credentials are the most common way in

30 %
of all attacks in 2024 began with valid, stolen credentials, not with a technical vulnerability
IBM X-Force Threat Intelligence Index 2025
73 %
of ransomware victims had a documented credential or infostealer leak in the year before the attack
Verizon Data Breach Investigations Report 2026
$4.67 m
is what a breach costs on average when it started with compromised credentials
IBM Cost of a Data Breach Report 2025

The window between leak and attack

Among ransomware victims with a documented credential leak, half of those leaks fell within the last 95 days before the attack. Spot it on day one and that time is yours to use.

365 days before 95 days Attack The leak surfaces on the dark web, somewhere in this period in 50% of cases, here

Source: Verizon Data Breach Investigations Report 2026, analysis of ransomware incidents with associated infostealer and credential leaks. The figure shown is the reported median, not the course of any single case.

How it works

Find it. Report it. Close it.

01 · Find

We search while you work

Marketplaces, forums, combo lists and infostealer logs are searched continuously for anything tied to your domains, mailboxes and accounts.

02 · Report

You hear about it immediately

A hit goes out as an alert, not into a quarterly report. It says which account is affected, where the find came from and how recent it is.

03 · Close

And you know what to do

Every finding comes with a clear recommendation: reset the password, end active sessions, enforce a second factor. On request we do it together with your IT team.

Features

What gets monitored

Domains, mailboxes and accounts in real time

New collections are ingested continuously and checked against your accounts, including the mailboxes nobody uses any more but which still exist.

Alerted within minutes, to the right people

By email, in the interface and, if you want, through an API into your ticket system. You decide who receives which alert.

A finding with a recommendation

Account, type of finding, source and timestamp, plus the order in which to act. Never a warning with no substance.

History as evidence

Every finding and every response is logged. That is exactly what auditors, cyber insurers and NIS2 want to see.

Who it is for

Worth it as soon as your people have an account somewhere

Manufacturers

Logins to customer, supplier and machine-vendor portals, spread across a lot of people.

Hospitals & care

Many accounts, high turnover and data where a single access becomes immediately notifiable.

Local authorities

Case systems, citizen portals and council information systems, each with its own login.

Anyone under NIS2

If you must demonstrate that risks are handled, you need documented monitoring, not good intentions.

Next step

Do you know what of yours is already out there?

We scan your domains once and walk you through the result. All we need are the domains. It is set up in about an hour.

WhatsApp💬