Company names leaked: what it means and what to do
Risk level: medium. Can you change it: no. Found in 1 breaches in this directory.
What this data is
The business name recorded against your account, either your employer or a company you own, often from business software, trade events, invoicing tools or directories.
The risk on its own
A company name is usually public already, so it rarely exposes a secret on its own. What it does is tell criminals which organisation you belong to. That is the first step in targeting you as an employee or owner rather than as a consumer.
The risk combined with other data
With your name, work email and job title it is the core of business email compromise. Criminals pose as your suppliers, managers or bank and ask for invoices to be paid to new accounts. If you own the business, it also exposes you to fake directory listings, fake domain renewal notices and trademark scams.
How criminals use it
A lookalike supplier email tells your accounts team that bank details have changed and the next invoice should go to a new account.
A fake domain or trademark renewal notice addressed to your company demands payment.
An attacker impersonates your IT provider, names your company and asks staff to install remote access software.
Fake invoices for services your company plausibly uses are sent to your accounts address.
What to do now
Set a firm rule that any change of supplier bank details is confirmed by phone on a number already on file, never the number in the email.
Warn staff who handle payments and IT access that the company's details were in a breach and impersonation attempts may follow.
Check the email security records for your company domain, SPF, DKIM and DMARC, so criminals cannot easily send mail as you.
Look at the headers of suspicious emails to see whether they really came from the supplier's domain.
Ignore renewal and listing notices unless they come from the registrar or directory you actually use.
Frequently asked questions
Our company name is public. Why does the breach matter?
Because it is now tied to named staff and their work email addresses, which lets criminals send targeted fraud rather than random spam.
What scam usually follows?
Invoice redirection, where a fake supplier email asks for payment to a new bank account. A callback to a known number before changing bank details is the most effective defence.
How do I stop people sending email that pretends to be my company?
Publish SPF, DKIM and a DMARC policy for your domain, then run an email security check to confirm they are set correctly.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.