Domain scorecard
Sample domain · public signals only · no internal access
No. An email association, reported password material, current credential validity, and current account compromise are separate evidence states. The source must support each stronger claim.
The breach slide usually starts with a familiar email address in large type. Then the label grows teeth: exposed credential, active risk, compromised user. I have seen how fast a room moves from a historical association to a present-tense accusation. The source may never have made that trip.
That usually happens one word at a time. An email address becomes a credential. A historical record becomes current exposure. A breach association becomes a compromised corporate account. By the time the sentence reaches the prospect, the evidence and the claim may be describing different things.
SCOUTz should not work that way.
What does a historical breach association prove?
At its narrowest, it means an identifier associated with the company’s domain appeared in a breach-related source. A responsible result should preserve the source, event or observation date when available, matched identifier, evidence type, freshness, and identity-match confidence.
That does not automatically establish that the person still works there, that password material was included, that an old password remains in use, that a current corporate credential is valid, or that the company account is compromised now.
Those are separate questions. They require separate evidence.
Is an exposed email address the same as an exposed password?
No. An email association, password material reported by a source, a hash, plaintext, a historical password, current credential validity, and current account compromise are different evidence states.
Even when a source reports password material, the result still needs context. Was the material plaintext, hashed, partial, or unspecified? Which breach produced it? When? Can the source establish that it belonged to the corporate account rather than an unrelated service? Can anyone establish whether it remains current?
If the source cannot answer those questions, the report should not answer them on the source’s behalf.
How should an MSP use breach evidence in a sales conversation?
Turn the evidence into a question, not a scare tactic.
“We found company email addresses associated with historical breach data. That does not tell us whether current passwords are exposed. How do you handle password resets and MFA review after a third-party breach?”
That sentence is still commercially useful. It gives the MSP a relevant reason to discuss identity hygiene, authentication, offboarding, and response procedures without pretending criminals are inside the building.
Why not display every person tied to the result?
Because company-first prospect research does not require a public wall of employee names, profile photos, personal accounts, or old passwords. Being able to collect something and needing to collect it are different questions.
SCOUTz should show the MSP enough context to understand the evidence, its limitation, and the next responsible question. Person-level detail needs a defined purpose, access boundary, retention decision, display rule, and deletion or suppression path. It should never exist merely because shock makes a memorable slide.
A breach match is a lead for investigation. It is not permission to invent the ending.