Skip to main content

What are the sources of the "Compromised Credentials" information?

Does "Compromised Credentials" include credentials traded on the dark web?

@Takashi_Ohmoto Compromised Credentials uses a number of sources for matching observed usernames to known data breaches.  These sources include dark web forums, publicly disclosed breaches, hacker dump sites, and more.  Once a username is seen and found in a dump, the event will provide details on the exact dump or source of the breach.  An example from a demo tenant is below:



 


Reply