# How to Spot & Verify Fake Data Breach Notices — LeakLens

> A practical guide on identifying phishing scams, fake data breach alerts, domain typosquatting, and verifying genuine security notifications.

## The Rise of Fake Breach Alerts

Cybercriminals frequently send fake data breach alerts pretending to be banks, password managers, or security services to trick users into revealing credentials.

## Red Flags of Fake Breach Notices

1. **Urgent Action Demands**: High-pressure threats to lock accounts within hours if you do not click a link immediately.
2. **Domain Typosquatting**: Emails coming from spoofed domains like `security@yourbank-secure.com` instead of the official domain.
3. **Suspicious Login Links**: Links leading to external domains instead of official login portals.
4. **Requests for Plaintext Passwords**: Legitimate security services will never ask you to email or submit plaintext passwords.

## How to Verify Genuine Incidents

- **Use Independent Public Registries**: Cross-reference reported incidents against independent registries like LeakLens.
- **Check Official Communication**: Visit the company's official security blog or contact customer support directly without using links in the email.
- **Verify using k-Anonymity**: Audit credential exposures safely using privacy-preserving k-Anonymity hash lookups.
