{"success":true,"data":{"id":"data-breach-credential-exposure-phish","label":"Fake dark-web breach notification — \"your credentials were found on the dark web, click to protect your account\" credential-harvest lure; real breach monitoring services never cold-email with click-through CTAs.","description":"Fake dark-web breach notification email — \"your credentials were found on the dark web, click to protect your account immediately.\" Cold inbound breach-notification emails with click-through CTAs are never legitimate. Real breach monitoring services (HaveIBeenPwned, credit bureaus, identity protection services) do not cold-email actionable CTAs that lead to credential-entry forms. This pattern is a phishing lure designed to harvest credentials under the guise of protecting them. Detection: dark web/data breach/credentials exposed vocabulary + click to protect/change password now/secure your account CTA + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +5. Source: GC1-R19; APWG dark web breach lure analysis 2025; FBI IC3 identity theft phishing advisory.","tier":"danger","category":"phishing","isThin":false}}