Compromised Credentials findings are powered by Hudson Rock, a trusted provider of high-quality compromised credential intelligence at scale.
The source of these credentials is from Stealers that are actively being sold on the dark web. They are not part of large public breach dumps (such as Have I Been Pwned), which makes them especially relevant and actionable.
How this works
Using data from Hudson Rock, we:
Compare compromised credentials against the domains listed in your company assets
Identify whether:
An employee in your organization has exposed credentials, or
Credentials connected to your company’s services are being sold on the dark web
Criticality types
The Compromised Credentials report includes two types of critical findings:
Company Employee
This means credentials belonging to your company’s employees are circulating on the dark web.
Why this matters
These credentials can be used to access internal systems
They significantly increase the risk of account takeover and lateral movement
What to do
Immediately disable or delete the account, or
Force a password reset
Company Service
This means credentials of external users (for example: Gmail users, students, or non-company domains) are being sold on the dark web and were stolen while using your service or company link.
Important to know
This does not mean your service itself was compromised
It means attackers are selling credentials that can be used to access your service without authorization
Why this matters
Unauthorized users may gain access to your platform
This can lead to abuse, fraud, or reputational risk
What to do
Review affected accounts
Invalidate exposed credentials
Apply additional access controls if needed
How to mitigate Compromised Credentials?
Step 1: Download Your Data (Touchless Download)
Navigate to the specific Compromised Credentials finding on the Panorays platform.
Click the Download button directly within the finding interface.
Complete the built-in confirmation flow to ensure secure, authorized access to the sensitive data.
An XLS file containing the relevant compromised credentials will download automatically.
💡 Note: Every download is automatically logged f in your Finding History and Activity Center.
Step 2: Remediate and Close
Use the downloaded file to resolve all compromised users (e.g., disabling accounts, forcing password resets, or invalidating session tokens).
Once you have remediated the risk, mark the finding as "Claimed Fixed" directly on the platform.
Following your next company assessment, the finding will be officially marked as Closed.
Why may the finding reopen?
A compromised credentials finding may reopen for one of the following reasons:
New credentials were discovered
→ These must be resolved again using the same process.
