Phishing Exposure Remediation Guides

What to do when phishing data surfaces your users' credentials — response guides for two audiences.

About These Guides

Phishing kits don't just steal passwords. Depending on the kit, a single capture can yield credentials, session cookies, MFA codes, and PII — and SpyCloud recaptures that data from criminal infrastructure, often within minutes of the phish event.

These guides translate SpyCloud phishing signals into specific response actions. Choose the guide that matches your audience and use case.


Choose Your Guide

🛒 For Consumers

For Consumers

For fraud, identity, risk, and security engineering teams. Covers how to act on phishing signals in the Consumer Threat Protection API — credential captures, target list inclusions, session revocation, and user notification templates.

Read the Consumer Guide →

🏢 For Employees

For Employees

For security operations and IT teams. Covers how to respond when employee credentials surface in phishing data — reset workflows, AiTM and MFA bypass context, and communication templates for affected staff.

Read the Employee Guide →


What These Guides Have in Common

Both guides are built around the same underlying signal: SpyCloud's recapture of phishing kit output from criminal infrastructure. Whether the exposed user is a customer or an employee, the same core principles apply.

SignalSeverityWhat It MeansRequired Response
Credential capture20+ (High)Plaintext password in criminal handsImmediate reset + session revocation
Phishing target list5 (Email Only)User targeted; phish may not have landed yetElevated monitoring + optional advance notification

📋

Scope Note: The breach_category and breach_title fields that identify phishing-sourced records are available on records from 2026 onward. Historical records pre-2026 do not yet carry these fields. Searching and filtering by these fields is on the product roadmap.


Related Reading


💬 Questions? Contact your SpyCloud Customer Success Manager or log in to submit a support ticket.