---
title: "Employees"
canonical: "https://kb.cynergy.app/space/GS/902791183/Employees"
format: markdown
---
The second scan launched after the onboarding of a new customer is the employees' scan.

Employees scan is mapping the organization's employees' data, creating a profile for each discovered employee's email, checking historical credentials leaks for each email address, mapping leaks names and dates of each email, and locating leaked clear-text passwords for each email.

Cynergy gathers the information from credential leaks in the deep and dark web, in addition to analysis of [Infostealer logs](https://cynergy-infostealer-iden-v8s3g7k.gamma.site/)

You will see the employee's name, email address, and password on this tab.

![image](media://ef8c5a99-e821-4d8b-9c52-f7fde487a463)

 

If Cynergy finds the leaked password, you will be able to lunch a password spraying scan by clicking on “Initiate scan.”

**Password Spraying**

- Collecting relevant employee data (employees' profile data and leaked credentials).
- Mapping for on-premise platforms- OWA, EWS, VPNs.
- Mapping for cloud-based platforms- MSOL (Microsoft Online Services), Office 365, Google Cloud Services (GMAIL, GCP, etc.), Atlassian (BitBucket, Confluence, Jira, etc.), GitHub and GitLab, Okta.
- Initiate password spraying process against collected platform - both cloud-based and on-premise

Once the password spraying scan is finished and you have successfully logged in with the credentials that were found, you will see where we succeeded in connecting to your environment under the “authorized” tab.

![image](media://e03299ad-cb43-44d4-9ac9-e4d09c5959d2)

### Raw data report explanation:

**Employee primary email address: ** The email address that was identified.  
**Employee leak indication: true/false**—If this email was found in any previous leak, the values will be true. Otherwise, the value will be false, meaning Cynergy has identified only the email.  
**Employee's leaked data:  **A clear-text password that was revealed as part of the data leak.  
**All email addresses found:** If any additional associated emails for the same employee are identified, they will be noted here.  
**Sources of data:** Where was this leak identified? 


 

<details>
<summary>Leak Sources:</summary>

Have I been pwned

Dehashed

Cloud of logs - Infostealers aggregate

AntiPublic

Collection1

NotSOCRadar

TelegramCombolists

ExploitIn

VerificationsIO

Adapt

Apollo

PDL

Exactis

NetProspex

Adobe

Dropbox

RiverCityMedia

Dodonew

Eye4Fraud

LinkedIn

Scrape

NetEase

Cit0day

YouveBeend

2844Breaches

ThePostMillennial

db8151dd

B2BUSABusinesses

Intelimost

ManipulatedCaiman

MyHeritage

MySpace

NotAcxiom

OnlinerSpambot

Ticketfly

PipingRock

HauteLook

NationalPublicData

ShareThis

Zynga

Disqus

Evite

Foodora

LeadHunter

Trello

TrikSpamBotnet

Tumblr

Twitter200M

Wanelo

Zomato

NazApi

SHEIN

iMenu360

Lastfm

QuestionPro

CDEK

AllegedATT

DataAndLeads

KnownCircle

KayoMoe

Luxottica

BVD

AhaShare

OpenSubtitles

Houzz

MindJolt

SpecialKSpamList

 CSM Lily

QuinStreet

JD

Zacks

MGM2022Update

MGM

VK

Youku

Xbox-Scene

Deezer

Epik

SlideTeam
</details>