I checked 50 small business emails against breach databases. Here's what I found.
Last week I ran 50 local business email addresses through HaveIBeenPwned — a free, public database that tracks data breaches.
43 out of 50 had at least one breach. Most had 3-5.
That means their passwords, and often their customers' data, are sitting in databases that anyone can access. The businesses had no idea.
Here's what was most common:
1. Reused passwords across everything
The business email password was the same one used for their website admin panel, their social media, and their billing software. One breach = everything compromised.
2. No two-factor authentication
Not on email, not on Google Business, not on Instagram. If someone has the password (which they do — it's in a breach database), they can walk right in.
3. Websites running outdated software
WordPress sites that haven't been updated in 2+ years. Known vulnerabilities publicly listed with step-by-step exploitation instructions.
4. Exposed documents on Google
PDFs with customer information, internal spreadsheets, and even login credentials — all indexed by Google and findable with a simple search.
The fix for all of this takes about 2 hours. Change compromised passwords. Enable 2FA. Update your website. Remove exposed documents.
If you run a small business and want to know where you stand, that's exactly what our Digital Security Checkup does. We check everything above using professional tools, then hand you a plain-English report with exactly what to fix.
It's like a health checkup, but for your online security.
