Alerts and triage
Alerts and triage Recovery emails for affected people When an address turns up in infostealer data, FathomWatch can email the person a link to a step-by-step recovery guide: what happened, which sites were affected, how to find and clean the infected device, and — in the right order — how to secure their accounts. People who use FathomWatch are always emailed about their own addresses (their sign-in address and verified personal addresses). For everyone else under your monitored domains, an org admin decides: Notifications → Email employees about infostealer exposures. It's off by default. Emails for your organization are sent on your behalf, with your organization's name and logo. The email never contains a password. The guide needs no sign-in, and its link expires after 30 days. Triage Every exposure has a status that your team moves along as it works: Status Meaning new Just arrived. investigating Someone is on it. resolved Dealt with — device cleaned, passwords changed. dismissed Not actionable. Each change can carry a note. Everyone who can see the exposure sees who changed what, and when. Leak inbox and export Leaks lists every exposure you can see, with search and filters for type, status and date. Export CSV downloads the filtered list, with passwords masked. Scheduled digests Org owners, admins and security analysts can have FathomWatch email a digest of new exposures at set times (for example 09:00 and 16:00) in your time zone, to the addresses you choose, optionally with a CSV attached. Set it up under Notifications → Scheduled leak digest. A digest is only sent when there's something new. Digests are part of the Organization plan. Webhooks To push exposures into other tools as they happen, see Webhooks.
FathomWatch documentation