FAQ

FAQ: infostealer detection and credential leaks

The questions that come up about compromised credential detection, our sources and how Stealed is used.

What is Stealed?
Stealed is a French platform that detects compromised credentials. We continuously collect and index infostealer logs, combo lists, criminal forums and Telegram channels, then alert you as soon as a credential tied to your perimeter appears there.
What is an infostealer?
An infostealer is silent malware that exfiltrates data from an infected device: credentials saved in browsers, session cookies, history, files, clipboard. The result, a full log of the machine, is sold or shared on criminal channels. A valid session cookie is an access without password and without MFA.
Why can't I search any domain?
Because a platform that lets your team search beyond your perimeter lets everyone else search yours. Stealed works in push mode: you receive what concerns the domains you have proven you own, and free search does not exist in the product. The public exposure check only returns aggregates.
Where does your data come from? Do you buy it?
No. We run our own collection pipeline on criminal sources, with no broker or third-party supplier. We put no money into the market that produces the leaks, and we depend on nobody for coverage or delay.
Is it legal to handle this data?
Our model was reviewed by a specialist law firm and relies on the French data protection authority's doctrine on leak intelligence. The conclusions are in the product's architecture: push delivery, proven perimeter, masked passwords, opposable audit log.
How is Stealed different from HaveIBeenPwned?
HaveIBeenPwned lists public database breaches, often months after the fact. Stealed monitors infostealer logs and criminal channels, where a stolen credential appears first, and alerts you on your perimeter within the hour, with the login URL, the source and the circulation history.
How does Stealed help with NIS2 and DORA?
Both texts expect continuous risk management and the ability to detect and notify quickly. Stealed provides continuous exposure monitoring, real-time alerting and an exportable log to document what was seen and handled. It is not a compliance module, it is proof that you monitor.
How does Stealed work?
We collect around 500 million credentials a day, normalise and deduplicate them, then correlate them with the domains and keywords of your perimeter. Less than an hour after its publication on a source, a credential that concerns you is available in your console and triggers your alerts.
My credentials were detected. What should I do?
1) Reset the account password and revoke its active sessions. 2) Check the account's recent activity. 3) If the device is infected by an infostealer, isolate and reinstall it before reconnecting anything. 4) Change the password everywhere it was reused. 5) Record the incident: Stealed keeps the history and the log.
Are you GDPR compliant?
Yes. Stealed is a French company, data is hosted in France by a French provider, on ISO 27001 and SOC 2 certified infrastructure. We apply minimisation: masked passwords, verified perimeter, access log.
Do you have an offer for MSSPs?
Yes. Partners get a multi-tenant workspace to operate their whole portfolio, with a score per client, white-label reports and a single API. Everything is described on the MSSP partners page.
Can I try Stealed for free?
Yes. Check your domain from the home page: you get aggregates immediately, then you can create your Free workspace to monitor that domain over time, no credit card required.