Skip to content
Calcrivo

Credential Exposure Calculator

Turn dark-web credential findings into the accounts genuinely at risk after cracking, reuse and MFA are accounted for.

Inputs

people
credentials
%

Many dumps hold only slow-hashed or truncated values that never yield a usable password.

%
%
$

Accounts Genuinely at Risk

11.0accounts

Exposure Rate

14.0%

Findings per employee monitored

Exploitable Credentials

147credentials

Expected Loss

$49,613

Risk Band

Medium

Step by step

  1. Values used

    Employees monitored = 3,000 people; Corporate credentials found in dumps = 420 credentials; Findings that are plaintext or crackable = 35 %; Exposed passwords still valid at work = 25 %; Affected accounts covered by MFA = 70 %; Cost per compromised account = 4,500 $

  2. Credential Exposure

    accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage).

  3. Accounts Genuinely at Risk

    = 11.0 accounts

  4. Exposure Rate

    = 14.0

  5. Exploitable Credentials

    = 147 credentials

  6. Expected Loss

    = 49,613

  7. Risk Band

    = Medium

How it works

A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over. Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.

Formula

Credential Exposure

accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage).

findings
Corporate credentials seen in breach dumps or dark-web listings
still-valid share
Exposed passwords that still authenticate against your directory

Frequently Asked Questions

How is Credential Exposure calculated?

accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage). A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over.

Why does Credential Exposure matter?

Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.

What values do I need to enter?

This calculator takes 6 inputs: Employees monitored, Corporate credentials found in dumps, Findings that are plaintext or crackable, Exposed passwords still valid at work, Affected accounts covered by MFA, Cost per compromised account. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Which findings should be rotated first?

Anything plaintext, anything on an account without MFA, and anything privileged — in that order. A plaintext credential for an unprotected administrative account is an incident, not a finding.

Why filter by 'still valid at work'?

Most findings come from consumer breaches where the user registered with their work email but a different password. Only the reused ones matter, which is why forced rotation on exposure should be scoped to confirmed matches rather than every hit.

You might also need