Turn dark-web credential findings into the accounts genuinely at risk after cracking, reuse and MFA are accounted for.
A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over. Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.
Credential Exposure
accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage).
accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage). A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over.
Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.
This calculator takes 6 inputs: Employees monitored, Corporate credentials found in dumps, Findings that are plaintext or crackable, Exposed passwords still valid at work, Affected accounts covered by MFA, Cost per compromised account. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Anything plaintext, anything on an account without MFA, and anything privileged — in that order. A plaintext credential for an unprotected administrative account is an incident, not a finding.
Most findings come from consumer breaches where the user registered with their work email but a different password. Only the reused ones matter, which is why forced rotation on exposure should be scoped to confirmed matches rather than every hit.