Grants staff find an applicant's email in a public breach-lookup service. What is the appropriate OSINT finding to report?
Select an answer to reveal the explanation.
Short Explanation
A breach lookup is a smoke detector, not a spare key. It tells you the address showed up in a public dump. It does not give grants staff permission to try leftover passwords on city systems.
Full Explanation
HIBP-class lookups answer whether an identifier appeared in public breach corpora. PORP breached-data OSINT reports that exposure; it does not authorize replaying secrets against municipal systems, cracking hashes, or redistributing recovered credentials. The grants briefing should state source class, date of the lookup, and that exposure is not proof of current account compromise. Refer credential-hygiene follow-up to the applicant and civic IT through proper channels.