What Is BTRA (Breach Threat & Risk Assessment)?
A breach hit is a fact. BTRA is the judgment call about how much that fact actually matters — here’s how the score is built.
Knowing that an email address "appeared in a breach" tells you almost nothing on its own — it might mean a throwaway newsletter signup got caught in an unrelated database leak, or it might mean an active corporate account has a working, unchanged password sitting in a criminal marketplace right now. BTRA — Breach Threat & Risk Assessment — exists to turn a pile of individual breach hits into one measured answer to the question that actually matters: how exposed is this identifier, really?
BTRA is built from four separate sub-scores, each measuring something distinct, rather than one opaque number. Credential exposure measures what fraction of the records found for an identifier actually contain a password or password hash — a hundred records that only leaked a username tell a very different story than ten records that leaked working passwords. Attack surface counts the number of distinct breach sources an identifier appears in, since exposure across many unrelated services is structurally riskier than one large leak. Digital footprint measures how many distinct types of data fields are exposed — an identifier tied only to an email breach is lower-risk than one where addresses, device fingerprints, and government IDs have all leaked somewhere. Stealer activity measures how much infostealer malware infection history is tied to the identifier — see "What Is a Stealer Log" for why that signal is weighted so heavily.
Those four sub-scores average into one overall BTRA score, bucketed into a LOW / MEDIUM / HIGH / CRITICAL tier — but the sub-scores themselves are always shown alongside the total in BreachINT’s exported report, not hidden behind it. That matters for anyone who has to defend a risk rating to a compliance reviewer, a client, or a court: "this identifier scored CRITICAL because it had a 90% credential-exposure rate across 14 breach sources, plus an active corporate-device stealer-log infection" is a defensible finding. A single unexplained number is not.
BTRA is deliberately scoped as an in-report metric, computed from what that specific investigation actually found — it isn’t pulling in an external reputation score or a black-box third-party rating. That keeps it transparent and reproducible: the same underlying breach and stealer-log data will always produce the same BTRA score, and every input that produced it is visible in the same document.
