Most break-ins at small businesses do not start with clever hacking. They start with a password that already leaked somewhere else. An employee signed up for a webinar or an online store years ago with their work email, that site got breached, and the email and password ended up in a dump that gets bought, sold, and traded. If that person reuses passwords, an attacker can now try that same combination against your email, your accounting software, and your bank.
The good news: checking whether your company addresses are in known breaches is free, takes about ten minutes, and does not require any technical skill. This guide walks through the check and, more importantly, what to do with what you find.
Where breach data comes from
When a website gets breached, the stolen database usually contains email addresses and passwords, sometimes hashed, sometimes in plain text. Those databases circulate for years. Criminals run them through automated tools that try every email and password combination against hundreds of popular services, a technique called credential stuffing. It works because people reuse passwords, and it is why a breach at a random forum in 2019 can turn into a drained bank account today.
There is also a newer and nastier source: infostealer malware. If an employee’s home computer gets infected, the malware grabs every saved password in their browser, including the ones for your business systems, and uploads them to logs that are sold in bulk. These stealer logs are behind a growing share of business email compromise cases.
Step 1: Check your own address first
Go to haveibeenpwned.com, the free breach search run by security researcher Troy Hunt. It is the industry standard, used by governments and Fortune 500 security teams. Type in your own work email address and press enter.
You will get one of two results: a green all clear, or a list of the breaches your address appears in, with the date and what kinds of data were exposed. Do not panic at a long list. Appearing in breaches is normal for any address that is more than a few years old. What matters is what was exposed and whether the passwords involved are still in use anywhere.
Step 2: Check your whole company domain at once
Checking addresses one at a time misses people, so check the entire domain. Have I Been Pwned has a domain search feature that shows every address at your domain that appears in known breaches. You prove you own the domain once, usually by adding a small DNS record or sending from a specific address, and then you get the full picture: every staff address, every ex-employee address, every old alias, and which breaches each one appears in. For most small business domains this is free.
If your IT provider manages your DNS, this verification step is a five minute request. If we manage your stack, this is part of what we watch continuously.
Step 3: Read the results like an attacker would
Not every hit is equal. Triage with three questions.
- Was a password exposed? A breach that leaked only your email and name is spam fuel. A breach that leaked passwords is an open door if that password is still alive anywhere.
- Is the account still active? Hits on ex-employee addresses matter more than people expect. If those mailboxes still exist and nobody watches them, they are a quiet way in. Disable or convert them to shared mailboxes with sign-in blocked.
- Does the breach include stealer logs? If a result mentions stealer logs, treat it as a live incident, not history. It means a device that someone uses for work credentials was infected at some point. That device needs to be found and cleaned, and every password saved on it needs rotating.
Step 4: Fix what you found
The fix list is short and none of it costs money.
- Reset every password that appeared in a breach, everywhere it was used, not just on the breached site. This is the whole reason credential stuffing works.
- Stop the reuse problem permanently with a password manager so every account gets a long unique password nobody has to remember. We wrote a rollout guide for teams: rolling out a password manager without the groans.
- Turn on MFA for email at minimum. With MFA in place, a leaked password alone is no longer enough to get in. Here is our step-by-step Microsoft 365 MFA guide.
- Close ghost accounts. Every ex-employee address that showed up in your domain results should be disabled or blocked from sign-in today.
Step 5: Make it a habit, not a one-time scare
Breaches do not stop happening because you checked once. Have I Been Pwned lets you subscribe for free notifications on your address and your domain, so you get an email when a new breach includes your people. Put a quarterly reminder on the calendar to review the domain report, especially after anyone leaves the company.
Managed IT providers, including us, typically fold this into dark web monitoring: continuous watching of breach dumps and stealer logs for your domain, with alerts and forced resets when something new shows up, so nobody has to remember to check.
Common mistakes
- Checking once, finding nothing, and concluding you are safe forever. The next breach has not happened yet.
- Resetting the password only on the breached site and leaving the same password alive on five others.
- Ignoring personal email addresses. Owners and bookkeepers often have work systems tied to personal Gmail accounts. Check those too.
- Skipping the conversation with the team. A two minute explanation of why the resets are happening turns grumbling into cooperation. Our phishing red flags guide pairs well with it.
Key Takeaways
- Leaked passwords from old breaches are one of the most common ways small businesses get compromised, because password reuse turns someone else’s breach into your incident.
- Have I Been Pwned is free, reputable, and lets you check your entire company domain at once.
- A breach hit only matters if the exposed password is still in use somewhere, which is why unique passwords plus MFA is the permanent fix.
- Stealer log results mean an infected device, not old history. Treat them urgently.
- Subscribe for breach notifications so the next one finds you prepared instead of surprised.
Want to know where your business actually stands? Take our free 12-question cyber-risk self assessment, or book the free 30-minute security awareness session for your team at /free-training/, in English, Spanish, or Portuguese, no obligation.
LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.