Credential Exposure Calculator
Turn dark-web credential findings into the accounts genuinely at risk after cracking, reuse and MFA are accounted for.
Inputs
Many dumps hold only slow-hashed or truncated values that never yield a usable password.
Accounts Genuinely at Risk
11.0accounts
Exposure Rate
14.0%
Findings per employee monitored
Exploitable Credentials
147credentials
Expected Loss
$49,613
Risk Band
Medium
Step by step
Values used
Employees monitored = 3,000 people; Corporate credentials found in dumps = 420 credentials; Findings that are plaintext or crackable = 35 %; Exposed passwords still valid at work = 25 %; Affected accounts covered by MFA = 70 %; Cost per compromised account = 4,500 $
Credential Exposure
accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage).
Accounts Genuinely at Risk
= 11.0 accounts
Exposure Rate
= 14.0
Exploitable Credentials
= 147 credentials
Expected Loss
= 49,613
Risk Band
= Medium
How it works
A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over. Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.
Formula
Credential Exposure
accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage).
- findings
- Corporate credentials seen in breach dumps or dark-web listings
- still-valid share
- Exposed passwords that still authenticate against your directory
Frequently Asked Questions
How is Credential Exposure calculated?
accounts at risk = findings × crackable share × still-valid share × (1 − MFA coverage). A raw exposure count overstates the problem, because most findings are stale, unusable or protected by a second factor. Applying the crackable share, then the share still valid at work, then the MFA coverage narrows hundreds of findings down to the handful of accounts an attacker could actually take over.
Why does Credential Exposure matter?
Dark-web monitoring services report the big number, and this is the arithmetic that turns it into a work queue you can size and a loss figure you can defend.
What values do I need to enter?
This calculator takes 6 inputs: Employees monitored, Corporate credentials found in dumps, Findings that are plaintext or crackable, Exposed passwords still valid at work, Affected accounts covered by MFA, Cost per compromised account. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Which findings should be rotated first?
Anything plaintext, anything on an account without MFA, and anything privileged — in that order. A plaintext credential for an unprotected administrative account is an incident, not a finding.
Why filter by 'still valid at work'?
Most findings come from consumer breaches where the user registered with their work email but a different password. Only the reused ones matter, which is why forced rotation on exposure should be scoped to confirmed matches rather than every hit.
You might also need
- Credential Stuffing Risk CalculatorCommonly used together
- Identity Theft Risk CalculatorCommonly used together
- Password Manager Coverage CalculatorCommonly used together
- Password Reuse Risk CalculatorCommonly used together
- Password Rotation CalculatorCommonly used together
- MFA Security CalculatorAlso in Password Security