What is dark web monitoring? A guide for businesses

HebeSec TechnologiesUpdated 6 min read

Dark web monitoring is the continuous search of breach data, infostealer logs, paste sites and dark web forums for information about your organization, such as staff email addresses and passwords, customer data or offers to sell access. It alerts you when something new appears, so you can reset accounts and contain the damage early.

On this page

What dark web monitoring does

The dark web is the part of the internet reached through anonymity networks such as Tor. It is small next to the open web, but a lot of stolen data is sold, traded and leaked there. Dark web monitoring watches those places, along with breach dumps and paste sites on the open internet, and tells you when your organization appears.

For a business, the main things to watch for are corporate email addresses and their passwords, logins stolen from employee devices, customer records, and posts that name your company or offer access to your network.

How company data ends up on the dark web

  • Breaches at other services. Staff sign up to third-party sites with their work email. When one of those sites is breached, the email and password end up in breach dumps, and a reused password opens company accounts.
  • Infostealer malware. Malware on a laptop, often a personal or contractor device, copies saved browser passwords, cookies and autofill data and uploads them as a “log” that is sold on dark web markets.
  • Ransomware and extortion. Groups that steal data publish it on leak sites when a victim doesn’t pay.
  • Misconfigured storage. Open databases and cloud storage are found by internet-wide scans and copied.
  • Phishing and insiders. Credentials captured by phishing pages and data taken by insiders are traded in the same places.

What dark web monitoring finds

FindingExampleWhy it matters
Exposed mailboxesA staff address listed in a breach dumpShows which accounts to check for password reuse
Leaked passwordsEmail and password pairs in a combolistCan be tried directly against email, VPN or cloud logins
Infostealer logsSaved logins from an infected contractor laptopOften recent, and can include session cookies
Leak-site and forum mentionsA post offering a company database for saleEarly warning of a breach you may not know about
Paste-site dumpsCredentials posted on a paste sitePublic, and copied quickly
Secrets in public codeAn API key pushed to a public repositoryGives direct access to systems or data

How dark web monitoring works

  1. Collect. New breach dumps, infostealer logs, paste-site posts, and dark web forum and leak-site content are gathered continuously.
  2. Match. Records are filtered down to the ones that name your domains, mailboxes, brand or other identifiers.
  3. Verify. Duplicates and old, recycled data are removed and each record is checked, so alerts point at real, current exposure.
  4. Correlate. Each leak is linked to the account, host or system it exposes.
  5. Alert. You get the finding, its source, how confident the match is, and the next step.

What to do when you get a dark web alert

Treat a credential alert as a possible compromise until you have checked it:

  1. Reset the password for the exposed account, and anywhere else the same password was used.
  2. End active sessions and revoke tokens, because stolen cookies can keep working after a password change.
  3. Turn on multi-factor authentication if the account doesn’t have it.
  4. Check sign-in logs for logins from new locations or devices since the leak date.
  5. Find the source. An infostealer log means the device it came from is infected: isolate it, clean or reimage it, and check what else was saved in its browser.
  6. Rotate exposed keys and secrets found in code or pastes.
  7. Decide whether it is a reportable incident, and record what you found and when.

Dark web findings and breach reporting rules

Several countries set short deadlines for reporting incidents and personal data breaches. In India, CERT-In’s directions require cyber incidents to be reported within six hours of being noticed, and the Digital Personal Data Protection Act requires notifying the Data Protection Board and affected people of a personal data breach. Indonesia’s Personal Data Protection Law (UU PDP) requires written notice within 3 x 24 hours, and Malaysia’s amended PDPA made breach notification to the Personal Data Protection Commissioner mandatory.

Dark web monitoring doesn’t replace legal advice on what to report. It can be how you find out about a breach in the first place, and these deadlines run from when you become aware.

Business dark web monitoring vs personal breach checks

Free breach-check websites, and the dark web alerts in some consumer security apps, tell one person whether their own email appears in known breaches. Business dark web monitoring works across a whole domain. It also covers infostealer logs and leak sites as well as old breaches, links each finding to the account or system at risk, and keeps watching, so new exposure shows up as soon as it is found.

What to look for in a dark web monitoring service

  • Domain-wide coverage, so every mailbox on your domains is checked, including ones nobody remembers creating.
  • Infostealer logs, not only old breach dumps, because stealer logs are often recent.
  • Verification and deduplication, so the same old breach doesn’t raise a new alert every month.
  • Context with each alert: the source, the date, the affected account or host, and what to do.
  • Same-day alerts rather than a monthly report.
  • Multi-tenant support if you are an MSSP monitoring clients.

How HebeGuard monitors the dark web

HebeGuard dark web monitoring checks breach data, infostealer logs, paste sites, public code repositories, data-broker sites, and dark web and ransomware leak sites for your domains and employee email addresses. Records are matched, deduplicated, verified and graded, then linked to the host or account they expose.

Alerts arrive the same day with the next step, such as resetting a password or rotating a key, in the same console as brand monitoring and attack surface management.

FAQ

Is dark web monitoring worth it for a small business?

Yes, if your staff use email accounts on your own domain. Stolen and reused passwords are a common way into small businesses, and a business service checks every mailbox on your domain with nothing to install.

Can dark web monitoring remove my data from the dark web?

No. Once data is copied and sold it can’t be recalled. Monitoring tells you what leaked so you can make it useless: reset passwords, end sessions and rotate keys.

How often should the dark web be checked?

Continuously. New breach dumps and infostealer logs appear every day, and recent credentials are the most useful to attackers.

What is the difference between the deep web and the dark web?

The deep web is everything search engines don’t index, such as email inboxes, online banking and private databases. The dark web is a small part of it that needs special software, such as the Tor browser, to reach, and it is where a lot of stolen data is traded.

What is a combolist?

A combolist is a large file of email and password pairs combined from many breaches. Attackers use it for credential stuffing: trying each pair against other services to find reused passwords.

We reply within one business day

See what an attacker can see of your company.

Send us your primary domain. We'll map your external attack surface and walk you through what we find.

sales@hebesec.com
What we'll cover
Asset inventoryExposure scoreValidated findingsDark-web hits
ISO 27001-alignedPCI-DSS-alignedNo agent