← All articles

Breach & lookalike exposure

Breached accounts and impersonation domains for your domain.

A website scan tells you about your site. The Exposure page (opened from any row on the Domains list) tells you about two things around your domain that an attacker cares about: leaked credentials and impersonation domains. Both pair naturally with a scan and are common starting points for real-world attacks — phishing, business email compromise, and credential stuffing.

Email breach monitoring

Add the staff email addresses at your domain that you want to watch — for example [email protected] — and Cyber Report checks each one against two independent signals:

  • Known breaches — which public data-breach lists the address appears in. If someone reused a breached password, that's an open door.
  • Infostealer infection — whether the address's logins were captured off a malware-infected machine. This is usually more urgent: when a device is infected, every saved password and active session on it is exposed at once. We show the scope — how many infected machines, when, which malware, and masked password hints so you can recognise an affected account — but never a usable password.

Either way, the fix is the same: force a password reset for that person, end their active sessions, and enforce MFA.

Everything happens here. You never have to sign up for or verify anything on another site. Because you've already proven you control the domain through our ownership check, you can add any address at that domain — and only at that domain, so the check can't be used to look up someone else's email.

Infostealer checks run for free by default (powered by Hudson Rock — no setup). Known-breach lookups are powered by Have I Been Pwned and are optional: until that source is connected, only the infostealer signal is shown for each address.

Lookalike / typosquat domains

Attackers register domains that look like yours — a swapped TLD (.net instead of .com), a typo, a homoglyph (rn for m), an extra hyphen, or a phishing prefix like login- — then use them to phish your staff or customers. This check generates those variants and reports which are actually registered and pointing at a live server.

It needs no configuration and works out of the box. It's entirely passive: we only ask public DNS resolvers whether the lookalike domains exist — we never contact them or your site. Not every registered lookalike is malicious (some may be legitimate businesses or defensive registrations you own), but each is worth reviewing, and reporting or monitoring the ones you don't control.

Note: to keep results bounded and fast, we check a capped set of the highest-signal variants, and approximate the registrable domain for multi-part TLDs like .co.uk. If a lookup can't complete, we say so rather than reporting a possibly-incomplete "none found".