Skip to main content

Compromised Credentials

Compromised Credentials findings are powered by Hudson Rock, a trusted provider of high-quality compromised credential intelligence at scale.

The source of these credentials is from Stealers that are actively being sold on the dark web. They are not part of large public breach dumps (such as Have I Been Pwned), which makes them especially relevant and actionable.

How this works

Using data from Hudson Rock, we:

  • Compare compromised credentials against the domains listed in your company assets

  • Identify whether:

    • An employee in your organization has exposed credentials, or

    • Credentials connected to your company’s services are being sold on the dark web

Criticality types

The Compromised Credentials report includes two types of critical findings:

Company Employee

This means credentials belonging to your company’s employees are circulating on the dark web.

Why this matters

  • These credentials can be used to access internal systems​

  • They significantly increase the risk of account takeover and lateral movement

What to do

  • Immediately disable or delete the account, or

  • Force a password reset

Company Service

This means credentials of external users (for example: Gmail users, students, or non-company domains) are being sold on the dark web and were stolen while using your service or company link.

Important to know

  • This does not mean your service itself was compromised

  • It means attackers are selling credentials that can be used to access your service without authorization

Why this matters

  • Unauthorized users may gain access to your platform​

  • This can lead to abuse, fraud, or reputational risk

What to do

  • Review affected accounts

  • Invalidate exposed credentials

  • Apply additional access controls if needed


How to mitigate Compromised Credentials?

Step 1: Download Your Data (Touchless Download)

  1. Navigate to the specific Compromised Credentials finding on the Panorays platform.

  2. Click the Download button directly within the finding interface.

  3. Complete the built-in confirmation flow to ensure secure, authorized access to the sensitive data.

  4. An XLS file containing the relevant compromised credentials will download automatically.

💡 Note: Every download is automatically logged f in your Finding History and Activity Center.

Step 2: Remediate and Close

  1. Use the downloaded file to resolve all compromised users (e.g., disabling accounts, forcing password resets, or invalidating session tokens).

  2. Once you have remediated the risk, mark the finding as "Claimed Fixed" directly on the platform.

  3. Following your next company assessment, the finding will be officially marked as Closed.


Why may the finding reopen?

A compromised credentials finding may reopen for one of the following reasons:

  • New credentials were discovered
    → These must be resolved again using the same process.

Did this answer your question?