Company profile / Cybersecurity

The Breach Was Someone Else’s. The Problem Was Yours.

HackNotice began by telling people when their data had escaped. Today it sells companies a more uncomfortable service: evidence that trouble at an employee account or distant supplier may already be heading their way.

In July 2018, HackNotice presented the internet with a modest invitation: make a list of the websites and companies you cared about, and it would tell you when one of them was hacked. The interface even called that list a “Hack Watchlist.” It was a pleasingly plain answer to a maddening question. If your details had escaped through a site you used once, who would tell you? The company’s answer was to watch for you.

The short version
  • HackNotice began with free breach and identity-leak alerts for individuals.
  • Its enterprise service followed in late 2018, built around exposed employee credentials and account-takeover risk.
  • Today it sells security teams monitoring for vendor breaches, leaked logins, ransomware activity and other external signals.
  • Published annual vendor-monitoring plans start at $15,000 for up to 50 vendors.

Eight years later, the watchlist is still the right image, but the person holding the pen has changed. The customer is now often a security team, and the names on the list belong to suppliers. A payroll vendor, a cloud service, a partner with access to customer data: each can have a breach that becomes somebody else’s incident. HackNotice has built its business around the interval between the first external sign of trouble and the moment an affected organization can act on it.

HackNotice's early Hack Watchlist interface with domains selected for monitoring
The original watchlist asked a wonderfully specific question: which websites should we worry about on your behalf?

The watchlist grows teeth

Founder and chief executive Steve Thomas came to this problem with a history in credential intelligence. He had founded PwnedList, a service concerned with exposed accounts, before working at SecurityScorecard. HackNotice’s public launch promised real-time monitoring for hacks and identity leaks, with free access for individuals. It gave users a reason to care about breach news that could otherwise feel like weather from another continent.

Michael Takla, who joined as co-founder and chief revenue officer in 2019, described the enterprise logic unusually clearly. The enterprise service had launched late the previous year, he wrote, and early customers had arrived. People reuse passwords. When a password appears in an unrelated breach, the employee’s company may acquire a problem it never directly caused. The leak happened elsewhere; the account takeover may happen here.

2018 / personWatch websites and identities for breach news.
2019 / workforceFind exposed credentials and alert employees who can recover accounts.
2026 / ecosystemWatch vendors, users and adversary activity; route credible signals into response.

That progression matters because it turns an alert into a job. A notice on its own may be interesting, perhaps alarming. A notice connected to an employee account, customer login or critical supplier has an owner. The owner can reset a credential, block access, ask a supplier for details or investigate an attack. HackNotice’s current language is “operational adversary intelligence,” a grand phrase for a very practical aim: show the security team something it can use before a more formal disclosure arrives.

“If you have ever been affected by a breach, you know how long it takes for companies to disclose how and what data was exposed.”
Steve Thomas, announcing HackNotice Actions in 2023

A bill for the awkward interval

The company raised a $7 million Series A in June 2022, led by Strategic Cyber Ventures with Lytical Ventures participating. At the time, it described itself chiefly as a company-wide threat awareness platform: teach employees about real threats and help them respond. In 2023 it added HackNotice Actions, which sends requests to breached companies on a person’s behalf. The request can ask what information was exposed or seek deletion of personal data; the user can track the reply. It is a small design admission with large consequences: telling someone their information has escaped is only the start of the work.

The newer enterprise pitch moves that lesson to security operations. HackNotice says it monitors ransomware leak sites, underground forums, breach datasets, criminal marketplaces and infostealer logs. The goal is to identify meaningful exposure affecting an organization or its vendors, enrich the signal, and send it to the people who can investigate. Its product pages also describe automated vendor questionnaires and AI-assisted summaries. These are the connective tissues between “a name appeared on a leak site” and “we contacted a supplier, checked our exposure and changed a control.”

HackNotice 4.0 product presentation showing its dashboard on a laptop
By version 4.0, HackNotice had swapped the simple watchlist for a fuller set of dashboards. The original question survived the redesign.

Published customer stories give the abstraction a shape, though the customers are mostly unnamed. One case describes a large technology company monitoring thousands of vendors because waiting for supplier disclosures left gaps in its response. Another describes a large tech customer receiving 12 actionable alerts in a month through tailored, API-based notifications. A separate case groups a restaurant chain, a credit union and a bank around leaked consumer credentials: different businesses, same fear that a stolen login could be reused before anyone noticed.

Those examples are company accounts, not independently audited outcome studies. Their usefulness lies in the workflow they expose. A vendor may be monitored independently of its own reporting. An alert can be sent to the right internal system. A fraud team can act on a leaked consumer login without waiting for a customer complaint. The product succeeds or fails at the handoff, when someone decides whether a signal deserves attention.

What does the early warning cost?

HackNotice’s public pricing makes the business model unusually legible for this corner of cybersecurity. The company sells annual subscriptions, with different meters for vendor counts, employee coverage, research credits and investigation hours. Its published third-party monitoring plans give a useful sense of scale:

StarterUp to 50 vendors$15,000 / year
GrowthUp to 150 vendors$30,000 / year
BusinessUp to 500 vendors$70,000 / year
EnterpriseUp to 1,000 vendors$120,000 / year

Published list prices for vendor monitoring; other services and custom packages are priced separately.

The price buys monitoring and workflow support, not the removal of every risk on a supplier list. It also reveals the buyer. A team with 50 vendors has a different operational problem from one with 1,000. The latter needs a way to rank alerts, route them, and remember what it did about each one. HackNotice’s differentiation rests less on claiming to be the only source of dark-web data than on attaching that data to people, companies and decisions. SecurityScorecard and other vendor-risk platforms offer alternatives; credential monitoring and broader threat-intelligence tools overlap with other pieces of the job.

$7mSeries A announced in 2022
12Actionable alerts in one published month-long customer example

The part worth stealing

A reader does not need HackNotice’s data collection machinery to borrow its most useful habit. Start with the list of suppliers and identities that could actually hurt the business if compromised. Decide in advance who receives a credible alert. Write down the first two actions for each kind of signal: verify the finding, then check what access or data the affected party has. Build a place to record the answer. Without that last step, a sophisticated feed produces a sophisticated pile of unread mail.

This approach has limits. External signals can arrive after the damaging act, and some breaches leave no public trace. A small organization with few vendors and a fast disclosure channel may need a simpler process. An alert stream without people available to validate and act on it can make the team slower, not faster. HackNotice’s own emphasis on fewer, higher-confidence signals is therefore less a marketing flourish than a condition for the product to be useful.

The company now presents AI-assisted investigation and automated assessments as the next stage. That may speed the work, but the real test remains remarkably old-fashioned: did the right person learn of a relevant problem in time to make a different decision? HackNotice began by asking which websites a person wanted to watch. Its grown-up question is harder, and better: when someone else is breached, how quickly can you tell whether it is yours to solve?