Free tool · No sign-up

Business Data Breach Checker

Check whether a work email or password has turned up in a known data breach. Breached credentials are how Australian businesses end up paying a scammer's bank account instead of their supplier's.

Password exposure check

Your password is never sent anywhere. Only the first five characters of its hash leave our server (k-anonymity).

Business email breach lookup

See which known breaches a work email address has appeared in.

Why a breach matters more than you think

A leaked password rarely gets used to steal data. It gets used to sit quietly inside an accounts mailbox and wait for an invoice worth redirecting. That's business email compromise, and it's the most expensive scam category for Australian businesses.

Silent access

Attackers read the mailbox for weeks, learning suppliers, amounts and payment timing before they act.

A real invoice, edited

The document is genuine. Only the BSB and account number change — which is why it clears internal review.

Funds gone in minutes

Once the payment leaves the rails it's usually swept offshore before anyone notices the mismatch.

What to do after a breach shows up

1. Rotate and lock down

Change the password everywhere it was reused and enable multi-factor authentication on email, banking and accounting software.

2. Check for mailbox rules

Look for forwarding or auto-delete rules an attacker may have left behind to hide their replies.

3. Verify bank details out-of-band

Never accept new account details from email alone. Confirm by phone using a number you already had on file.

4. Put a gate in front of payments

RILLA Shield's 15-layer defence checks every invoice, supplier and BSB before funds leave — including our Verified Supplier Vault and ABA file checker.

Frequently asked questions

What is a business data breach checker?

It's a free lookup that tells you whether a work email address or password has appeared in a publicly known data breach. Breached credentials are the starting point for most business email compromise and invoice fraud attacks in Australia.

Is it safe to check a password here?

Yes. Passwords are never sent anywhere. We hash the password in our server and send only the first five characters of that hash to the Pwned Passwords range API, so the full password and full hash never leave RILLA Shield.

What should I do if my business email shows up in a breach?

Rotate the password everywhere it was reused, turn on multi-factor authentication, and treat every payment instruction from that mailbox as unverified until it's confirmed out-of-band. Breached mailboxes are the number one route into invoice redirection fraud.

How does a data breach lead to invoice fraud?

Attackers buy breached credentials, read the mailbox quietly, then wait for a real invoice. They resend it with changed bank details from a lookalike domain. The invoice looks legitimate because it usually is — only the BSB and account number have changed.