Skip to main content

Data Breaches Guide

See which of your people appear in known third-party data breaches, what data leaked, and notify them — all from inside Spikerz.

Written by Ron Storfer

What Data breaches does

Your team's work accounts show up in third-party data breaches all the time — an old design tool, a food delivery app, a photo service. When one of those services is breached, the email address, username, password or phone number your team member used there ends up in a public dump. Attackers then take those credentials and try them against the accounts that actually matter: your brand's social media accounts.

Data breaches continuously scans known breach data for the people connected to your workspace and shows you exactly who was exposed, in which breach, and what kind of data leaked. When a password is among the leaked data, Spikerz flags it so you can act before someone else does.

Two things make this useful in practice:

  • It is people-first. You don't just get a list of breaches — you get a list of your people and what happened to them.

  • You can act from inside the product. One click notifies the affected person so they can change that password.

Where to find it

In the left sidebar, under Hacking protection, click Data breaches.

The Data breaches page, People tab

At the top of the page you'll see when the data was last refreshed (for example Last update 4 hours ago) and a Scan now link to trigger a fresh scan on demand.

The two tabs: People and Breaches

The same data, viewed from two directions. Pick whichever matches the question you're asking.

People tab — "who on my team is exposed?"

One row per person. Use this when you're doing a security review of your team, or when you want to know how badly one individual is exposed.

  • People — name, plus the email addresses that were found in breaches.

  • Breaches — how many separate breaches this person appears in.

  • Last detected — the date of the most recently detected breach for that person.

  • Affected data — the categories of data that leaked, shown as chips.

Breaches tab — "which breach hit us, and who did it hit?"

One row per breach. Use this when you hear about a breach in the news, or when you want to scope the blast radius of a single incident.

The Breaches tab

  • Breach — the breached service, with its logo.

  • Detected on — when the breach was detected.

  • Affected people — avatars of the people from your workspace who appear in it, with a +N counter when there are more than three.

  • Affected data — the categories of data that leaked in this breach.

Reading a row

Affected data chips. Each chip is one category of leaked data — Email addresses, Usernames, IP addresses, Phone number, Geographic location, and so on. When more chips exist than fit the column, a +12-style counter appears at the end.

Passwords chips are highlighted in red. This is the one to look at first. A leaked email address is an annoyance; a leaked password is an active route into an account, especially if it was reused.

Hover to see the full value. Anything truncated — a long email address, a +2 email counter, a +9 people counter — expands into a tooltip on hover.

Hovering an email counter on the People tab reveals every address

Hovering the affected-people avatars on the Breaches tab lists every name

Narrowing the list

Quick filters

Three chips sit directly above the table, each with a live count:

  • All — everything Spikerz has found.

  • Leaked passwords — only records where a password was among the leaked data. This is the fastest way to get to the items that need action today.

  • Breaches in last 7 days — only recently detected breaches.

Search

The search box filters the current tab as you type — by person on the People tab, by breach on the Breaches tab.

Filter

Click Filter to combine conditions. The filter set is cross-referenced, so each tab lets you filter by the other dimension:

On the People tab — filter by Breach name (show only people caught in specific breaches), Detection date, or Affected data.

Filter options on the People tab

On the Breaches tab — filter by Person name (show only breaches that hit specific people), Detection date, or Affected data.

Filter options on the Breaches tab

Breach name, person name and affected-data filters are searchable multi-select lists, so you can tick several values at once. Detection date offers All time, Today, Yesterday, 7 days, 30 days, 3 months, or a custom date range. Affected data covers Password, Email address, Username, IP address, Phone number, Geographic location and more.

Sort

Click Display to open Sort by, then pick a field and toggle ascending or descending. The options mirror the table's own columns.

The Display menu with sort options

  • People tab — sort by name, number of breaches, or last detected. Last detected uses the most recently detected breach for that person. Default: number of breaches, descending — most-exposed people first.

  • Breaches tab — sort by breach name, detection date, or number of affected people. Default: detection date, descending — newest breaches first.

Pagination

The footer shows the current range (for example 1 – 25 of 180), page controls, and a Show selector for how many rows to display per page.

The details drawer

Click any row to open a side drawer with the full breakdown. What you see depends on which tab you came from.

From the People tab: one person, all their breaches

Person details drawer

The drawer header shows the person's name, their affected email addresses, and a Notify button. Below that, Affected emails groups everything by email address — because one person often has several, and each one carries its own exposure history. Under each address you'll find a card per breach, showing the service logo, its name, the detection date, and the data categories that leaked from it. A search box lets you jump straight to a specific address or service when a person has a long history.

From the Breaches tab: one breach, everyone it hit

Breach details drawer

The drawer header shows the breached domain and its detection date. Affected people then lists every person from your workspace found in that breach, each with their own Notify button and their own set of affected-data chips — so you can see at a glance which of them had a password exposed and notify them one by one. This view is searchable too.

Notifying an affected person

Finding the exposure is only half the job. The person who reused that password is the one who has to change it, and Notify tells them.

You'll find Notify in three places: in the person drawer header, next to each person in a breach drawer, and on the Data breach tab of a user's profile in Permissions management.

Click it and Spikerz sends the person a notification letting them know their data was found in a breach. A confirmation toast appears at the top of the screen — Successfully notified [name] — or, if the send fails, Failed to notify [name], in which case simply try again.

Success and failure notification toasts

Who you can and can't notify

Spikerz can only notify people who are members of your workspace. If a breach turns up someone who isn't — a former contractor, an agency contact, a personal address that was never added — the Notify button is disabled, and hovering it explains why: Can't notify people outside your workspace.

Notify disabled for a person outside the workspace

You can still see their full exposure; you just need to reach out to them through your own channels. If they should be in the workspace, add them in Permissions management and the Notify button becomes available.

Breach data inside Permissions management

Breach exposure also shows up where you manage people. Open Permissions management, click a user, and switch to the Data breach tab in their drawer.

The Data breach tab in a user profile in Permissions management

This view sits alongside Permissions and User protection, which is the point: when you're deciding how much access a person should have, their breach exposure is part of that decision. A banner at the top offers to Notify them directly, and each breach card shows counted chips — 4 passwords, 2 email address, 1 username — so you can see the scale of the exposure, not just its type.

A person with leaked passwords and admin access to your brand accounts is a combination worth resolving quickly.

When the list is empty

Empty state: Looks good, no breaches to show yet

An empty list with Looks good means one of two things: no breach data has been found for your people, or you haven't connected any assets yet. If it's the latter, connect your assets first — Spikerz needs to know who your people are before it can monitor them.

What to do when you find something

A practical order of operations:

  • Start with the Leaked passwords filter. Exposed passwords are the only category that gives an attacker a direct route in. Everything else is reconnaissance material.

  • Notify the affected people and ask them to change that password wherever they reused it — including on your social accounts.

  • Check reuse against your social accounts. If a leaked password matches one still in use on a connected account, treat it as compromised and rotate it now.

  • Turn on two-factor authentication. A leaked password is far less dangerous when it isn't enough on its own.

  • Review their access. In Permissions management, check whether the exposed person still needs the level of access they have.

  • Re-check the recent view. Use Breaches in last 7 days as a routine check so new exposures don't sit unnoticed.

Still have a question about Data breaches? Start a conversation with us from the Messenger and we'll help.

Did this answer your question?