Technical Issues & FAQs

Knowing What to Do If You Receive an Exposed Password Notification

1.2 min read

| September 18, 2026

Overview

You may receive an email from “noreply-security@automated.extensiv.com” notifying you that credentials associated with your account were identified as exposed on the internet.

Receiving this notification does not mean that your account or Extensiv has been hacked or compromised. This is a precautionary security measure intended to help you protect your account when credentials associated with it have been identified in external threat intelligence sources.

 

Why did I receive this email?

We use a threat intelligence platform that monitors for security risks, including credentials that may have been exposed outside of Descartes or Extensiv systems.

When credentials associated with an account are identified as exposed, we trigger a password reset to prevent any unauthorized access from occurring.  

 

What should I do?

If you receive this notification, we recommend that you:

  • Reset your password immediately. On the login screen, click “Forgot Password” to reset. Your account will be locked until a new password is successfully set.
  • Do not reuse the exposed password. If you use the same password for other accounts or services, change it there as well.
  • Sign out of any active sessions associated with the account.
  • If the account is no longer actively used, consider having it disabled.
  • As an additional precaution, run an up-to-date antivirus or malware scan on devices used to access the account and remove any saved or cached credentials from your browser. 

 

Where could my password be exposed?

Credentials can become exposed in many ways, including phishing attempts, compromised third-party websites, malicious software, previous data breaches, or malware on a user's device.

Exposed credentials may eventually appear in underground forums, dark web marketplaces, or other sources monitored by threat intelligence providers.

 

What does the notification look like?

If you receive this notification, follow the instructions in the email and reset your password promptly. 

 

Does this mean my account was hacked?

No. The notification alone does not indicate that someone accessed your account.

It means credentials associated with your account were identified as potentially exposed through external threat intelligence. We are notifying you proactively so you can secure your account before those credentials could potentially be misused.

If you have questions or need assistance resetting your password, please contact Support.

Share additional feedback about this article

Not finding the help you need?

Contact Support