March 18, 2026
Reading your exposure report
If your identifier is found, the report leads with two headline numbers: total compromises and total machines. Compromises count how many separate infection events involved your identifier; machines count how many distinct devices those came from. If both numbers are the same, you were likely compromised once per device. If compromises is higher, the same machine may have been infected more than once.
The exposure entries
Each exposure is one infected machine. We show the approximate date it was logged, a rough location, the operating system, and which antivirus (if any) was running at the time — useful context for judging how the infection likely happened. Below that, services, browsers, and detected malware processes are shown as tags, not a narrative, so you can scan them quickly.
The credential entries
Passwords are never shown in full. Instead you get a masked version, the character length, which character classes it used (uppercase, lowercase, digits, symbols), and two occurrence counts: how many times it showed up in this specific exposure, and how many times globally across everything we've indexed. Use the masked shape and length to recognize which real password it corresponds to — that's enough to know what to rotate without us ever displaying the plaintext.