The credential compromise blind spot

Credential stuffing, password reuse and third-party breaches are among the most common initial access vectors. The NCSC's OT guidance emphasises replacing default credentials — but you cannot protect accounts you do not know are compromised.

Have I Been Pwned (HIBP) has been the de facto reference for breach exposure for over a decade. The problem is operationalisation: security teams check HIBP ad hoc, identity teams maintain separate spreadsheets, and the service desk only learns about a compromised account when the user calls because they cannot log in.

Breach response should start as tickets, not side conversations.

What Pwned monitors

Pwned is an Echo-9 plugin that integrates GLPI with Have I Been Pwned so service desk and security teams see exposure where they already work.

  • User security status — a Security Status tab on each GLPI user record with clear breach state and detail
  • Password breach checks — HIBP k-Anonymity checks when users are created or updated, so plaintext passwords never leave your environment
  • Domain monitoring — polls HIBP for organisational domain breaches and can auto-create high-priority GLPI tickets
  • VIP monitoring — group-based scanning on a short cycle for high-value accounts such as executives and privileged users
  • Vendor breaches — fuzzy-matches GLPI manufacturers against known HIBP breaches, surfacing supply chain credential risk
  • Users at Risk dashboard — summary metrics and manual triggers for the team that owns identity risk

How it works technically

Password and email checks use HIBP's k-Anonymity model: only a partial hash prefix is sent to the API, so the full credential is never transmitted. Domain and VIP monitoring runs on configurable polling cycles. When a breach is detected, Pwned can raise a high-priority GLPI incident automatically — with context attached — so remediation starts in the service desk workflow, not a separate security tool.

This matters for Cyber Essentials and ISO 27001 evidence: you can demonstrate that credential exposure is monitored, ticketed and tracked to resolution within the same platform that holds your incident records.

Pwned within the Echo-9 security stack

Pwned is not a SIEM replacement. It complements the broader stack:

  • Wazuh detects suspicious login behaviour, file changes and endpoint threats
  • Pwned monitors whether identities were exposed in known external breaches before an attacker uses them
  • GLPI holds the ticket, the user record and the remediation workflow

When Wazuh flags an anomalous login and Pwned shows the account appeared in a breach last week, analysts have both signals in connected systems — not two consoles and a phone call.

The bottom line

Breach monitoring belongs in your service desk, not a separate silo.

Pwned turns Have I Been Pwned from a website security teams check occasionally into an operational control that creates work where work gets done. Credential hardening starts with knowing which credentials are already compromised.

Request Pwned

Pwned is available as an add-on to Echo-9 GLPI subscriptions and implementations.