---
title: "Compromised Employee Credentials"
canonical: "https://kb.cynergy.app/space/MD/899416369/Compromised%20Employee%20Credentials"
format: markdown
---
**Description **

Attackers are constantly disclosing and selling combinations of username/email and password of users from various compromised and hacked websites and databases.

Many of these leaks are being publicized on Deep Web and Darknet websites and tools. 

Since most people are using the same credentials for multiple platforms and websites. Attackers are collecting and using the leaked credentials to expand their attacks from one platform to many others.

**Hacker's View**

As a hacker, I constantly collect leaked credentials and combos( combinations of emails and passwords in the following format email:password) to then reuse the credentials in multiple attacks:

- Credential stuffing
- Identity theft
- Access to privileged networks - VPN services and SaaS applications of companies.

**Mitigation**

The mitigation for a leaked credentials incident is divided into two parts:

- Immediate action -
  - Validate the password leaked is still valid - Cynergy scan
  - Reset password for the affected user - can be atomated via Active Directory integration.
- Security awareness training for users, teaching them not to use work accounts for external platforms, to enable, Multi-Factor Authentication(MFA) whenever possible, and to use Single Sign-On(SSO) wherever applicable

**Cynergy’s View**

Cynergy constantly collects and indexes leaked password combinations in a large data lake. in addition, Cynergy uses 3rd party APIs to identify credential leaks that may not be collected by the platform. Cynergy has a unique algorithm that tries to identify if the leaked credentials can be used in multiple different SaaS applications and VPN services.

Once an Employee scan is running against your defined domain. Cynergy platform will try to identify all the employees that had their credentials leaked. Once a leak of credentials for an employee was identified, Cynergy will then allow you to conduct an active scan to validate the credentials against services. 

![image](media://09036527-50d7-45ee-9dc6-8d7f78dc8487)

If the credentials were identified, Cynergy will then issue an alert to the scan initiator, and to the email of the user, asking him to modify the password for the affected service. This way the remediation process is faster. and will not require IT attention.