Tool 4

Are your employee and customer credentials already for sale?

Work out which credential exposure applies to your organisation, what a single stolen login would reach, how you would find out, and what an Indian entity owes when it is confirmed.

In short
For an organisation of any size the question is not whether corporate credentials are circulating but which ones and how recent — Bitsight’s underground corpus holds over 170 billion credentials and takes in more than four billion a week, most from infostealer malware rather than from any breach of the employer. What differs between organisations is blast radius, detection and what a confirmation obliges.

Work out your exposure

Describe how your identity estate is actually built. Nothing below is a lookup — this page does not search anything on your behalf, and it does not estimate a number of leaked credentials, because a figure nobody can source is worth less than a consequence that follows from what you told it.

Your identity estate
5exposures apply, with 6 gaps that would turn one into an incident

In scope: 500 employee accounts, contractor and vendor accounts in the same directory, a customer login base under a million. Every finding below follows from what you selected — nothing here is a lookup, and no count of leaked credentials is estimated.

What an underground search would return

  • Exposed
    Compromised credentials attributed to your domains

    Corporate credentials tied to named systems — the SSO portal, a Jira or Confluence tenant, a SaaS console — recovered mostly from infostealer malware logs rather than from any breach of yours. This is the finding that exists for essentially every organisation of your size, which is why the useful questions are which accounts, how recent, and whether the passwords still work.

    Bitsight Identity Intelligence — Compromised Credentials
  • Exposed
    Stealer-malware logs from devices you do not manage

    You allow personal or otherwise unmanaged devices to reach corporate mail or SaaS, so a corporate credential can be captured on a machine your EDR has never seen and your logs never record. An infostealer takes the saved browser passwords, the session cookies and the host details together — which is why a password reset alone frequently does not close it, and why nothing in your own telemetry will ever show the theft.

    Bitsight Identity Intelligence — endpoint and device data
  • Exposed
    Access to your estate could be listed for sale

    You run internet-facing corporate access — a portal, VPN, webmail or remote desktop — which is exactly the asset class brokered on underground markets, sold as working access rather than as a password. A listing names the company, so the first sign is often a broker advertising you by name. Where a listing exists, it can be bought back and the access revoked, but only by someone who is looking.

    Bitsight Identity Intelligence — Access Currently for Sale
  • Exposed
    Customer credentials, and the reuse that follows them

    You hold customer logins. Credential stuffing replays passwords breached elsewhere against your login page, so a take-over needs no breach of yours — only a customer who reused a password. Successful attempts look exactly like genuine logins in your own telemetry.

    Bitsight Identity Intelligence — Compromised Credentials

What one working credential reaches

  • Gap
    A standard user credential logs in unchallenged

    Multi-factor authentication on privileged accounts only defends the accounts an attacker does not need first. Intrusions that begin with a bought credential almost never begin at an admin account — they begin at an ordinary one, and privilege is escalated from inside. The unchallenged account is the whole of the entry problem.

    Control design
  • Gap
    One credential, every application federated to Microsoft Entra ID

    Single sign-on through Microsoft Entra ID means one working credential reaches every federated application at once, without a second authentication anywhere along the way. Concentration is the point of SSO and it is not the problem; concentration without a second factor in front of it is.

    Control design
  • Gap
    Contractor accounts sit inside the same directory

    Contractor and vendor accounts live in your directory but sit outside the device management, security training and leaver process that cover your own staff. They are credentials with your access and someone else’s hygiene, and an account left live after an engagement ends is one nobody is watching.

    Control design

How you would find out

  • Exposed
    You would find out when somebody tells you

    Nothing watches the underground for your credentials today, so a leaked password is invisible to you until it is used, or until a bank, a customer, a researcher or a regulator tells you. Credential theft leaves no trace in your own logs — the theft happens on someone else’s machine and the login that follows is valid — so this is not a gap your existing monitoring covers.

    Detection design
  • Gap
    Being told starts your six-hour clock

    CERT-In’s Directions run from noticing the incident or being brought to notice of it, so the third party who tells you starts the clock at the moment they tell you — not at the moment you finish confirming it. Learning about your own exposure from outside means the first hours of a six-hour deadline are spent establishing what happened, and an investigation still in progress does not pause it.

    CERT-In Directions, 28 April 2022, s.70B(6) IT Act, 2000
  • Holding
    An exposed account can be disabled in Microsoft Entra ID directly

    Bitsight Identity Intelligence integrates with Microsoft Entra ID, so a confirmed exposure can trigger a reset or a disable against the directory rather than a ticket. That is the difference between a response measured in seconds and one measured in the helpdesk’s working hours.

    Bitsight Identity Intelligence — identity provider integrations

What a confirmed exposure obliges

  • Gap
    CERT-In binds you regardless of who regulates you

    Unauthorised access to an IT system and data breaches are both in the Annexure I list of incidents that must be reported within six hours. The Directions are made under the Information Technology Act rather than under any financial-sector statute, so they reach every entity in India — regulated, unregulated, listed or private — and a sectoral filing never discharges them.

    CERT-In Directions, 28 April 2022, s.70B(6) IT Act, 2000
  • Gap
    Customer logins make you a Data Fiduciary

    Holding customer credentials means you determine the purpose and means of processing digital personal data, which is what a Data Fiduciary is — a status that attaches from what you do with the data rather than from who licences you. The breach duty is not live yet: Rule 7 of the DPDP Rules, 2025 and section 8 of the Act commence on 13 May 2027, and from that date every affected Data Principal is intimated with no threshold for size or severity, with a full report to the Data Protection Board within seventy-two hours.

    DPDP Act, 2023 and DPDP Rules, 2025 — G.S.R. 846(E), 13 November 2025

Indicative, and not a determination that any credential of yours has been exposed. Whether a reporting obligation is triggered is a determination for your compliance and legal team.

Take this away as the Identity Intelligence check on your domains

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Why this is not a question of whether

The instinct on reading a headline like the one at the top of this page is to check whether you have been breached. Almost always, you have not been — and the credentials are circulating anyway. Corporate logins reach underground markets by two routes that have nothing to do with your own security: infostealer malware on a device that had the password saved in a browser, and password reuse at a service that was breached and was not yours.

Both routes leave nothing in your telemetry. The theft happens on someone else's machine, and the login that follows is a valid authentication by a real account. This is the part that makes credential exposure different from every other finding on a security rating: the rest of the estate is measured from the outside, and this is measured somewhere you cannot see at all.

The scale is the argument. Bitsight Identity Intelligence publishes the size of what it has collected:

  • 170B+ credentials in the database.
  • 4B+ compromised credentials added weekly.
  • 1,500+ underground forums and marketplaces crawled.
  • Under a minute from collection to enriched alert.

At four billion new credentials a week, an organisation of any size is not asking whether some of its logins are in there. It is asking which ones, how recent they are, and whether the passwords still work — and those are questions with answers.

What “already for sale” actually means

A credential dump and an access listing are different products, and conflating them is why the second gets missed. A dump is raw material: a username and a password that may or may not still work. A listing is finished goods — working access to a named organisation, advertised by company name and priced, because a broker has already done the work of confirming it opens.

That is the step between credential theft and ransomware, and it is the one that can still be interrupted. Where a listing exists it can be bought back and the access revoked before it is used. It cannot be interrupted by anyone who is not looking for it, which is what the detection group in the tool above is asking about.

What a confirmed exposure obliges in India

Unauthorised access to an IT system and data breaches both appear in CERT-In's Annexure I list of incidents reportable within six hours. Those Directions are made under section 70B(6) of the Information Technology Act rather than under any financial-sector statute, so they bind every entity in India regardless of who licenses it, and a sectoral filing never discharges them.

The trap is where the clock starts. CERT-In's six hours run from noticing the incident or being brought to notice of it, so if a bank, a customer or a researcher is the one who tells you, the clock started when they told you — not when you finish confirming it. An organisation that does not monitor the underground is, by construction, an organisation that learns about its own exposure from outside.

Customer logins add a second track. Holding them makes you a Data Fiduciary, and from 13 May 2027 a confirmed exposure means intimating every affected Data Principal with no threshold for size or severity, plus a full report to the Data Protection Board within seventy-two hours. There is no DPDP breach clock running on an incident today, which makes now the cheap time to rehearse it.

For every clock a single incident starts, and who each filing goes to, use the incident reporting clock. For the terms above — Data Fiduciary, Data Principal, the six-hour clock, DAKSH — see the Indian regulatory vocabulary.

This page performs no search and makes no claim about any specific organisation. The findings it produces are consequences of the inputs supplied, not observations. The corpus figures are Bitsight's own, quoted from its Identity Intelligence product page and checked on 21 August 2026; the module is licensed and has no public API, so the lookup itself is run by BitScore against a licensed tenant on domains a requester confirms they control. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

How would I know if my employees’ credentials are for sale?
Not from your own logs. Credentials are usually stolen by infostealer malware on a device you do not manage, so the theft happens outside your telemetry and the login that follows is valid. Absent underground monitoring, organisations find out when a bank, a customer, a researcher or a regulator tells them — which under the CERT-In Directions starts a six-hour reporting clock at the moment of being told, not at the moment you finish confirming it.
Does a credential leak mean we have been breached?
Usually not, and that is what makes it easy to dismiss. Most corporate credentials on underground markets come from infostealer malware on an employee’s or contractor’s device, or from a breach at an unrelated service where the same password was reused. Nothing of yours was penetrated. The credential still works, and an attacker using it produces an authentication event indistinguishable from a genuine one.
What is “access currently for sale”?
Working access to a named organisation, brokered on underground markets as a product rather than as a password — a VPN session, a portal login, a remote-desktop foothold, priced and advertised by company name. It is the step between credential theft and ransomware, and the reason a listing matters more than a credential dump: someone has already done the work of confirming the access is live. Where a listing exists it can be bought back and the access revoked, but only by someone looking for it.
Does multi-factor authentication solve credential exposure?
It changes the consequence, not the exposure. The credential is still circulating and still sold; MFA is what stops it being sufficient. Two qualifications matter: coverage on privileged accounts only defends the accounts an attacker does not need first, since intrusions begin at ordinary accounts and escalate from inside, and a stolen session cookie can carry an attacker past the prompt entirely.
Do we have to report a credential leak to CERT-In?
Unauthorised access to an IT system and data breaches both appear in the CERT-In Annexure I list of incidents that must be reported within six hours. The Directions are made under section 70B(6) of the Information Technology Act rather than under any financial-sector statute, so they bind every entity in India — regulated or not, listed or not — and a sectoral filing never discharges them.
Do exposed customer credentials trigger DPDP obligations?
They will, from 13 May 2027. Holding customer logins makes you a Data Fiduciary, because you determine the purpose and means of processing digital personal data. Rule 7 of the DPDP Rules, 2025 and section 8 of the Act commence on that date, and from then every affected Data Principal is intimated with no threshold for size or severity, with a full report to the Data Protection Board within seventy-two hours. There is no DPDP breach clock running on an incident today.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of entity-scope, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools