Ethiack Docs

Leaked Credentials

Why leaked credential findings can't be retested automatically, and how to close them

Leaked credential findings work differently from other findings in the portal: they can't be retested automatically. This page explains why, and what to do once you've responded to one.

What a leaked credentials finding means

Ethiack's continuous testing checks your organization's domains and identities against known breach and leak sources. When a credential tied to your organization turns up in one of these sources, Ethiack raises a finding so your team can respond quickly.

Unlike most findings, this one isn't describing something on your attack surface. It's evidence of an exposure that already happened on a third party's systems, at a point in time, before Ethiack ever detected it.

Why it can't be retested automatically

Retesting works by having Ethiack's engine re-examine one of your assets to confirm whether a vulnerability is still present. Leaked credentials don't fit that model, for two reasons:

  • There's no asset on your surface to re-examine. The exposure happened on infrastructure Ethiack has no visibility into or access to (a breached third-party service, a paste site, a leak database). Retesting checks your assets again; there's no equivalent check to run against systems that were never part of your surface.
  • Rotating the credential doesn't change what already happened. The finding records that a credential was exposed at a specific point in time. Changing the password stops that credential from working, which is the right response, but it doesn't alter the fact that the exposure occurred. There's no "not found again" result for the engine to confirm, the way there is for a vulnerability with a live technical footprint.

This is consistent with how retesting works across the portal: findings need a current, checkable condition on your surface for the engine to validate. Leaked credentials describe a past event instead, so retesting isn't something the engine can perform for this finding type. See Retesting for how automatic retesting works for other findings.

How to close a leaked credentials finding

Step 1: Reset the exposed credential

Change the password for the affected account, and enable multi-factor authentication (MFA) where it's available. If the same password is reused anywhere else, rotate it there too: credential reuse is one of the most common ways a single leak turns into multiple compromised accounts.

Step 2: Mark the finding as Fixed

Update the finding's status to Fixed once the credential has been rotated.

No retest button

Because there's no retest to run, the status is based on your confirmation rather than an engine check: no retest button will appear once a leaked credentials finding is marked as Fixed, unlike other finding types.

On this page