Skip to content
privacybeginner#dark-web-monitoring#identity-theft#data-breach#infostealer#threat-intel

How Dark Web Monitoring Works: Sources, Alerts and Limits

Where dark web monitoring gets its data, how it matches your email or domain, what an alert means, the gaps it cannot close, and what to do next.

Bank apps, password managers, antivirus suites and identity theft plans all now offer some form of "dark web monitoring". The pitch is simple: we watch the criminal underground and tell you when your details show up. What happens behind that pitch is less mysterious than the name suggests. It is data collection, indexing and matching, and the quality of each step decides whether the alert you get is useful.

This guide explains the mechanics. If you want background on Tor and hidden services first, read what the dark web is. For the malware that produces the most valuable monitoring data, see the infostealer guide.

The basic pipeline

Every monitoring service, from a free email lookup to an enterprise platform, runs the same four steps.

  1. Collect leaked data from wherever it is published, traded or sold.
  2. Parse and normalise it: split files into records, extract emails, usernames, passwords, URLs, card numbers and ID numbers, and remove duplicates.
  3. Index the records so they can be searched by identifier.
  4. Match and alert: compare the index against the identifiers customers registered, and send a notification when there is a hit.

Steps two to four are engineering. Step one is the hard part, and it is where vendors differ most.

Where the data comes from

Leaked data reaches criminals and researchers through several distinct channels. Each has a different freshness and a different level of risk for you.

SourceWhat it containsTypical freshnessHow useful an alert is
Breach dumpsA company's database: emails, password hashes, names, addressesMonths to years after the breachMedium. Tells you which password to retire
CombolistsEmail and password pairs compiled from many older breachesOften recycled, sometimes years oldLow to medium. Lots of duplicates and stale passwords
Infostealer logsSaved passwords, cookies, autofill data and the login URLs from one infected deviceDays to weeksHigh. Points to a specific infected machine
Phishing-kit dropsCredentials typed into fake login pages, sent to a criminal's inbox or botHours to daysHigh, if the vendor gets access
Paste sites and Telegram channelsSamples, free leaks, advertising for paid dataVariesMedium. Often partial
Closed forums and private salesFresh databases, access listings, full logsFreshHigh, though coverage is thin

Breach dumps are the classic source. When a company is breached, its user table often ends up sold and later leaked for free. Have I Been Pwned (HIBP) is the best-known index of these. Its FAQ is explicit that when breach emails are loaded, "no corresponding passwords are loaded with them", so HIBP tells you that you were in a breach, and you work out which password to change.

Infostealer logs are now the richest source. A stealer infection captures what a browser stores, including the URL each password belongs to and live session cookies. HIBP indexes some stealer logs too, and specialist vendors are built around them. Hudson Rock describes its data as "sourced directly from threat actors" and offers free domain and email searches against what it says are over 33 million infected computers. SpyCloud says it recaptures credentials and session cookies from more than 105 infostealer families.

Paste sites and Telegram are where data is advertised or given away. Telegram channels in particular distribute free stealer-log batches to attract buyers for paid ones. HIBP's FAQ warns that an email appearing in a paste "does not immediately mean it has been disclosed as the result of a breach", which applies to every vendor's paste alerts.

Scraping versus human access

There are two ways to collect. Automated scraping crawls open forums, paste sites, public Telegram channels and leak sites. It is cheap, broad and slow to reach anything gated. Human intelligence (HUMINT) means analysts who hold accounts in closed forums and private channels, build reputation, and acquire data before it circulates widely. SpyCloud, for example, says it "infiltrates criminal communities" to recapture data before it spreads. Human access reaches fresher material, and it costs far more, which is one reason enterprise products are priced differently from consumer ones.

Most consumer monitors buy their data

A small number of companies collect leaked data at scale. Many more license feeds from them and put their own app on top. Constella, for example, describes reseller, OEM (white-label) and API partner models for its identity data. Two different brand names can be checking the same underlying database, so comparing products by the size of a headline record count tells you little.

Suppliers versus resellers

It helps to sort the market into three layers.

LayerRoleExamples
Collectors and suppliersAcquire and parse leaked data, sell feeds and APIsSpyCloud, Hudson Rock, Constella, Recorded Future (Identity Intelligence)
Free public indexesLet anyone check an email, domain or passwordHave I Been Pwned, Hudson Rock's free search tools
Resellers and bundlersPackage licensed data into consumer apps, banking add-ons and identity theft plansIdentity protection suites, password manager breach alerts, bank and card add-ons

Recorded Future says its Identity Intelligence draws on "infostealer logs, malware combo lists, database dumps" and other sources. Each supplier publishes its own scale figures, and they measure different things (records, credentials, infected machines), so treat them as marketing numbers that cannot be compared directly.

If you are choosing a consumer product, our identity theft protection comparison covers the bundles. The question to ask any vendor is simple: which sources do you collect yourself, and which do you license?

How matching works

You register identifiers, and the service checks them against its index.

Illustrated cybersecurity scene for How Dark Web Monitoring Works: Sources, Alerts and Limits
Illustration for How Dark Web Monitoring Works: Sources, Alerts and Limits.
  • Email address: the most common. Matches breach records, combolists and stealer logs.
  • Domain: enterprise monitoring. Matches every record with an email at your domain, plus stealer-log entries where your login pages appear as the URL. This second type catches customers and contractors whose devices saved a password for your site.
  • Phone, username, card number, bank account, national ID number: consumer plans add these. They match fields in breach dumps and fraud listings.

Good services also tell you what was found alongside the identifier: a plaintext password, a hash, an address, a cookie, or the URL of the site the credential belongs to. That context decides what you should do.

For a domain-level view of stealer exposure, our stealer exposure check shows counts of infected employees and users and which login URLs were captured for a domain.

What an alert actually means

Alerts read alike, but they describe very different situations.

"Your email was found in a data breach." A company you used leaked its user data. Your risk depends on what was in it. If passwords were included, retire that password everywhere you reused it.

"Your password was found." A plaintext or cracked password tied to your email appeared, usually in a combolist or stealer log. Change it on every account that shares it.

"Your device or credentials were found in an infostealer log." One of your devices, or a device that saved your login, was infected. This is the most serious common alert, because stealer logs often include session cookies that let an attacker skip the password and MFA prompt entirely. See session hijacking for why.

"Your Social Security number was found on the dark web." This is the vaguest alert. It rarely tells you where, when or alongside what the number appeared. US SSNs have leaked in so many large breaches that this alert says more about the state of US identity data than about a new event in your life. Treat it as a reason to freeze your credit, which you should do anyway.

Some 'dark web alerts' are phishing

The FTC has warned about emails claiming your personal information is for sale on the dark web that are themselves scams. Do not click a link or call a number in an unexpected alert. Open the monitoring app or site you signed up for directly and check there.

The hard limits

Monitoring is useful. It also has gaps that the marketing rarely mentions.

Lag. Data has to leak, reach a channel the vendor watches, be acquired and be processed before you hear about it. Breach dumps can surface years after the intrusion. By the time a combolist alert reaches you, the password may have been tried against hundreds of sites.

Coverage. No one sees everything. Private sales, invite-only forums and data held by a single criminal never reach most indexes. The Consumer Federation of America's survey work found many consumers wrongly believe monitoring can remove their data or stop criminals using it. It does neither.

Cookies and sessions. A service that only matches email and password pairs misses the most dangerous part of a stealer log: the session cookies. Changing a password does not always end sessions an attacker already holds. Only some vendors report cookies, and only enterprise products usually act on them.

False positives and stale data. Combolists recycle old passwords, and parsers mislabel fields. Expect alerts about passwords you retired years ago.

No removal. Leaked data cannot be pulled back from criminal hands. Monitoring is a warning system.

A clean result proves little. "No results found" means the vendor has no record. It does not mean your data is safe.

Consumer and enterprise monitoring

ConsumerEnterprise
WatchesYour email, phone, SSN, cardsEvery account at your domains, plus customer logins
Data depthUsually breach and combolist hitsStealer logs with cookies, machine details and URLs
ResponseAn app notification and a support lineAutomated password resets, session revocation, SOC tickets
Bundled withCredit monitoring, insurance, restoration helpThreat intel, digital risk protection, IAM integrations

Enterprise teams use monitoring to catch employee credentials before an initial access broker turns them into a foothold. The Snowflake customer breaches in 2024 started from stealer credentials, some years old, that were never rotated. Our Snowflake breach guide covers that case.

How to defend when an alert fires

Work through this in order.

  1. Verify the alert at the source. Open the monitoring service directly, never through a link in the message.
  2. Find out what leaked. Email only, a password, a cookie, or identity data such as an SSN. The response differs.
  3. Change the exposed password everywhere it was used. Use a password manager so every account gets a unique one.
  4. Turn on MFA, preferably passkeys or an authenticator app, starting with email and banking.
  5. Sign out of all sessions. Our session kill switch lists where each major platform lets you revoke sessions and sign out everywhere.
  6. For a stealer-log alert, clean the device first. Scan or reinstall the infected machine before changing passwords on it, or the new passwords will be stolen too.
  7. For identity data, freeze your credit with each bureau. The FTC notes a freeze is free, and it blocks new credit accounts opened in your name. IdentityTheft.gov builds a recovery plan if fraud has already happened.
  8. Watch the accounts tied to the leak for password reset emails and new device logins.

Our after a data breach checklist goes deeper on each step.

Sources & further reading