Data Breach Intelligence
Security research, threat analysis, and breach intelligence from the xonPlus team.
Latest Insights
Stop Account Takeover: Step Up Auth on New Breach Exposure
When a user's email lands in a newly indexed breach, ask that one account for a stronger check at its next sign-in, and leave everyone else alone. The research, 149 breaches added in a year, what leaked decides the factor, a policy you can ship, and two ways to wire it.
Employee Credential vs Dark Web Monitoring: Which Do You Need?
Most teams need employee credential monitoring first: it's cheaper, quieter and hands you something to fix the same day. Dark web monitoring is the add-on. What each one sees, what the 2025 and 2026 reports say about stolen logins, and four questions to decide.
Breach Exposure in Your Product: 6 Patterns That Work
Show facts, not verdicts. A count and a date, a dated list with chips, one plain sentence per breach, the trend rather than the total, what's new to the index, and an empty state that promises nothing. Each pattern tied to the API field it's built from.
Client Domain Breached? The MSSP's First 48 Hours, Step by Step
An alert names a client domain. Verify it's real and new, scope who and what, tell the client in their own words, fix the handful of things that matter. Six hours of work inside a 48-hour window.
How to Choose a Breach Monitoring Vendor: 12 Questions
Every breach monitoring demo looks the same. These twelve questions tell vendors apart, with a scorecard you can paste into an RFP and our own answers, weak ones included.
Free vs Paid Breach Monitoring: Exactly Where We Draw the Line
Your own domain and inbox are free on XposedOrNot, no card, no account. Other people's domains are xonThreatIntel+. Same breach index on both sides. The whole line, the edge cases, and what the money actually buys.