Mayfield Intelligence Operations Start a pilot

01 Monitoring & detection

Data Breach & Credential Monitoring

Credentials leak constantly, usually through somewhere you do not control. Most organisations find out from the attacker.

Start a pilot

A single reused password on a breached third-party service is enough. Infostealer malware on a home device harvests a session token and the attacker never needs the password at all. Neither event touches your network, so neither shows up in your logging — but both give someone a working route into your systems.

We track breach databases, combolists and infostealer logs for your domains, executives and staff, and we alert you in real time with exactly what to rotate. The value is in the interval: hours or days between exposure and use, rather than discovery after the fact.

01 What you receive

Deliverables.

Every engagement produces a written, sourced deliverable — not a dashboard login you will never open.

01
Domain watch
Continuous matching of your email domains against breach corpora and new dumps.
02
Executive watch
Personal as well as corporate accounts for named senior staff, where authorised.
03
Real-time alerting
Notification on match, with the credential type and the source of exposure.
04
Remediation guidance
What to rotate, what to revoke, and which controls the exposure suggests are weak.

02 Method

How it runs.

  1. 01

    Baseline

    An initial sweep establishes what is already exposed before monitoring begins.

  2. 02

    Monitor

    New corpora and dumps are matched against your watch list as they surface.

  3. 03

    Alert

    Material matches reach you immediately with the detail needed to act.

  4. 04

    Review

    Periodic reporting on exposure trend, repeat offenders and third-party sources.

04 Common questions

Do you store our credentials?

No. We record that a credential associated with your domain has been exposed, its type and its source. We do not retain plaintext passwords, and we do not test exposed credentials against your systems.

Can you monitor executives’ personal accounts?

Only with their explicit, documented consent. Personal-account exposure is often the more serious risk for a senior figure, but monitoring it without consent would be neither lawful nor appropriate, so we set it up properly or not at all.

How quickly would we hear about a match?

Material matches are alerted as soon as an analyst has confirmed them, typically within hours of the source surfacing. Lower-severity findings are batched into routine reporting rather than interrupting you.

Tell us what you would want watched. We will scope a pilot on it, in writing, before anything is agreed.