Getting started
Getting started FathomWatch watches stolen-credential data for your organization's email domains and the addresses you choose, and tells you when one of your people turns up. Today it monitors infostealer logs — data copied off infected devices by password-stealing malware. More sources are on the roadmap. Sign in Sign in to the FathomWatch portal with your account; if your organization uses its own sign-in provider, you're sent there. FathomWatch works in two contexts: Organization — you're acting for your organization. Exposures, detectors, webhooks and settings belong to the organization. Personal — your own account. You can monitor your own email addresses (with a Personal plan). Switch between them with Switch user/org at the bottom of the sidebar. Set up monitoring FathomWatch only reports what your detectors match. Detector Who can add it How it's verified Domain Org admins Choose one of your organization's verified domains. Active immediately. Custom keyword or regex (e.g. a brand name or internal hostname) Org admins Reviewed by our team before it goes live. Personal email (up to 5) Anyone, in personal context Confirmed with a code sent to the address. Open Detectors to add them. A detector only matches data that arrives after it's created. Who sees what Within an organization: Org owners and admins see every exposure in the organization. Members of any group your admins map to the Security analyst role see every exposure too. Admins set this under Dashboard → Group → role mappings, using the group names from your sign-in provider. Everyone else sees only exposures of their own address. Exposures of someone's personal addresses are visible only to them. What an exposure shows Each exposure lists the affected account, the sites whose logins were stolen, and the password masked: only the first few characters are shown so the owner can recognise it. The full password is never stored. A SHA-1 hash of the password is included so you can check it against public breached-password lists. A credential that turns up again later isn't reported twice. Next steps Alerts and triage — employee recovery emails, digests and statuses. Webhooks — send exposures to your SIEM, ticketing or chat tools.
FathomWatch documentation