Dark web monitoring
Most of what is sold as dark web monitoring is not the dark web at all. It is breach dumps, infostealer logs and criminal forums, and the value is in what you do when your name appears in one.
What is actually being monitored
The phrase covers several very different sources, and it is worth being precise about which ones matter.
Credential breach data
Username and password pairs from breaches of third party services, where your people reused a work address. Widely available, easy to check, and still useful, because password reuse has not gone away.
Infostealer logs
This is the part that matters most and the part most often glossed over. Infostealer malware on a personal or unmanaged machine harvests saved browser passwords and, more importantly, active session cookies. A stolen session cookie skips the password and frequently skips multi-factor authentication too, because the session is already authenticated. If one of your users appears in stealer log data, the first response is not a password reset, it is a session revocation.
Criminal forums and leak sites
Ransomware leak sites, initial access broker listings, and forum posts naming an organisation, a domain or a supplier. Being named on a leak site is rarely the first you should hear of your own incident, but a supplier being named is often the first you hear of theirs.
Exposed data
Documents, source code and configuration turning up in public repositories, paste sites and misconfigured storage. Less dramatic than the forums and more frequently the actual cause of a breach.
What we do with a hit
A finding on its own is an alert, not an outcome. We verify it is genuinely yours rather than a recycled entry from an old dump, establish which account and which system it affects, and tell you what to do in order: revoke sessions, rotate credentials, check the account for activity that should not be there, and look for what the same attacker may already have done. Where the exposure came from a device rather than a website, the device is the problem, and we will say so.
What it will not do
It will not remove your data. Once something is in a dump it is in circulation permanently, and any vendor promising takedown of breach data is selling something that cannot be delivered. It will not prevent an attack, and it is not a substitute for detection. What it does is shorten the gap between your credentials becoming available and you knowing about it, and that gap is the window attackers work in.
Where it fits
Credential exposure monitoring is worth most alongside the controls that make a stolen credential less useful: multi-factor authentication, conditional access, short session lifetimes, and alerting on unusual sign-ins. On its own it tells you that you have a problem. Combined with those, it tells you a problem was contained.
Common questions
How is this different from a free breach checking site?
Free services tell you an email address appeared in a named breach. They do not generally cover infostealer logs, which is where current passwords and live session data appear, and they will not tell you which of your systems the credential opens. The monitoring is the cheap part. Knowing what to do about a hit is the part worth paying for.
Someone’s credentials have appeared. What now?
Revoke active sessions first, before resetting the password. A reset on its own does not invalidate a stolen session cookie, and that is the mistake we see most often. Then reset the password, review the account for unfamiliar sign-ins, mail rules and consented applications, and establish whether the exposure came from a compromised device.
Can you get our data removed?
No, and neither can anyone else. Data in criminal circulation is copied and re-listed continuously. Anyone telling you otherwise is charging for a promise they cannot keep. The realistic goal is to make the exposed data useless as quickly as possible.
Do you monitor our suppliers as well?
We can. A supplier breach that reaches your data is your incident regardless of whose systems failed, and supply chain exposure is increasingly what clients ask about in their own assurance questionnaires.
Is looking at this data legal?
Yes. We work from commercially licensed breach and stealer log datasets and from publicly accessible sources. We do not purchase access to criminal marketplaces, and we do not use credentials that appear in them.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.