In 2025, over 10 billion compromised credentials from various breaches were sold on the dark web and hacker forums. It is highly likely that your employees' login details are among them: from various online services where they register both privately and professionally. And if they use the same or similar passwords for company systems, you have a problem.
Dark web monitoring is a systematic activity tracking illegal online spaces (the dark web, paste sites, hacker forums, Telegram) to detect whether data belonging to your organisation appears there. It is not hacking nor an illegal activity; it is an intelligence capability that gives you a critical head start.
What is the dark web and how does it differ from the deep web?
Terminology is important here: terms are often confused:
- Surface webcontent indexed by standard search engines (Google, Bing). It makes up approximately 4% of the total internet.
- Deep web. Content accessible via the internet but not indexed by search engines, banking systems, corporate intranets, email systems, the Netflix catalogue. Entirely legitimate and constituting the vast majority of the internet.
- Dark webthe intentionally hidden part of the internet, accessible only via specialised software (most commonly Tor - The Onion Router). The dark web contains both legitimate uses (anonymous journalism, bypassing censorship) and extensive criminal ecosystems.
For security monitoring, we focus on the dark web (Tor.onion sites), but also clearnet platforms such as Telegram channels, paste websites (Pastebin and alternatives), and closed hacker forums accessible via the regular internet.
How corporate data leaks onto the dark web
Data breaches at third parties
The most common scenario: your employees register on various online services (LinkedIn, Dropbox, Adobe, different e-shops, forums) using a company email address. If such a service suffers a data breach, the company email and password (or its hash) end up in a breach database. If an employee uses the same or a similar password for company systems, an attacker will link them.
So-called "combo lists", merged databases of millions of login credentials from various breaches, are freely available for download or sale at low prices on the dark web. Attackers use them for credential stuffing attacks against corporate VPNs, email accounts, Office 365 or other portals.
Infostealer malware
An infostealer is a category of malware specifically designed to steal login credentials and other sensitive data from an infected device. Popular families include Redline Stealer, Raccoon Stealer, Vidar, and LummaC2.
Infostealers typically collect:
- Login credentials stored in browsers (saved passwords in Chrome, Firefox, Edge).
- Session cookies: an attacker can take over an authenticated session without knowing the password.
- Cryptocurrency wallets.
- Files from the Desktop and Documents folders.
- System information (IP, hardware, installed software).
Stolen data are called "logs" and are sold on dark web marketplaces (formerly Genesis Market, now various alternatives) or Russian Market. Each "log" contains the complete profile of the infected device. An attacker buys a log for a few dollars and gains access to everything the victim had stored in their browser, including access to corporate VPNs, email or cloud systems.
Direct attacks and exfiltration
After successfully infiltrating an organisation, attackers exfiltrate data and offer it for sale before (or instead of) deploying ransomware. Ransomware groups such as LockBit, Cl0p or Black Basta operate dedicated "leak sites" on the dark web where they publish stolen data from companies that refused to pay the ransom.
What to look for on the dark web: Corporate asset monitoring
Effective dark web monitoring tracks these categories of corporate assets:
Login details
- Email addresses on corporate domains (@vasfirma.cz) in combo lists and breach databases.
- Combination of corporate email and password from infostealer logs.
- Login credentials for specific corporate systems (VPN, Microsoft 365 tenant, Jira, GitHub).
Technical information
- IP addresses of corporate infrastructure discussed in the context of vulnerabilities.
- Configuration files or source codes from company repositories.
- Offers of initial access to an organisation: 'access brokers' sell company access as a commodity.
Company documents and data
- Published documents (contracts, internal reports, customer data) on ransomware leak sites.
- Mentions of corporate assets on hacker forums (discussions about potential attacks, sharing information about vulnerabilities).
Tools and methods for dark web monitoring
Commercial platforms for business monitoring
- Recorded Future: komplexní threat intelligence platforma s rozsáhlou pokrytostí dark webu, hackerských fór i clearnet zdrojů. Nabízí API pro integraci se SIEM.
- Flashpointspecialisation in criminal forums and ecosystems. Flashpoint analysts actively infiltrate closed forums.
- Digital Shadows (ReliaQuest)focus on brand monitoring and digital risk protection, including the dark web.
- Cybersixgill. Access to dark web sources in real time.
- KELAspecialisation in financial and identity theft data.
Free and open-source tools
- Have I Been Pwned (HIBP)Free check of emails in breach databases. The Domain Search function checks all email addresses on a given domain: an excellent free starting point.
- DeHashedsearching breach databases, free tier available.
- IntelligenceXarchive of websites, pastes from websites and sources from the dark web.
What to do upon discovering compromised data
Data leak detection is just the beginning: the key lies in the correct response:
- Reset passwords immediately for any compromised accounts found. Regarding corporate email or SSO, enforce a reset for the entire domain.
- Check the logs to detect whether compromised login credentials have already been misused, logins from unusual IP addresses or at unusual times.
- Revoke session tokens - A valid session may persist even after a password reset. Force users to log in again.
- Turn on MFA for disabled accounts: and ideally for all accounts if not yet implemented.
- Inform affected employees - explain the situation to them and give them clear instructions on how to behave.
- Carry out a targeted safety investigation - regarding the infostealer log, the device may have been compromised. Consider a forensic analysis or reinstallation of the operating system.
- Assess GDPR impacts - if the leak involves personal data, consider reporting it to the Office for Personal Data Protection within 72 hours.
SecureOn.cz provides dark web monitoring as part of threat intelligence services, continuous monitoring of corporate assets, alerting upon discovery and assistance with responding to detected leaks. Contact us to set up monitoring.
Preventive measures: Reduce the risk of leaks
Monitoring is reactive: ideally combine it with preventive measures:
- Password manager required. Unique, strong passwords for each service eliminate the risk of credential stuffing attacks from breached databases.
- MFA everywhere. Even a compromised password is useless without a second factor.
- Prohibition on using the company email for private purposeslimits exposure of the corporate domain in breach databases.
- EDR on all devicesdetection and blocking of infostealer malware.
- Staff traininghow not to install illegal software, how to identify malware distribution.
Conclusion: Visibility is the first condition of defence.
You cannot defend against what you do not know. Dark web monitoring provides visibility into spaces where attackers trade your data and discuss your vulnerabilities. This visibility gives you time to react, reset passwords, strengthen authentication, alert employees, before an attacker actively exploits the information.
In today's world, dark web monitoring for companies with any digital presence is as fundamental as a firewall. It is not a paranoid luxury. It is a hygiene necessity.