Stolen employee credentials regularly appear on dark web marketplaces from unrelated service breaches. Dark web monitoring services provide early detection of exposed credentials, enabling organisations to reset passwords and prevent attacks before credentials are exploited. Here's what's happening, why it matters, and what you can do about it.
What Is the Dark Web?
The "dark web" refers to parts of the internet that are not indexed by standard search engines and require specialised software (typically the Tor browser) to access. It is home to a range of legitimate privacy-focused communities and journalism, but also to criminal marketplaces where stolen data, malware, drugs, and access credentials are traded.
It is important to distinguish the dark web from the "deep web" — which is simply any part of the internet not indexed by search engines, including your email inbox and banking portal. The criminal activity is concentrated on specific dark web forums and marketplaces.
What Gets Traded on the Dark Web?
The categories of stolen data most relevant to businesses include:
- Credential dumps: Username and password combinations harvested from breached websites. When staff reuse passwords, a breach of an unrelated website can expose their work account credentials.
- Session cookies and tokens: Stolen from compromised devices by information-stealing malware (infostealers), these allow attackers to access accounts without needing the password.
- RDP access: Direct access to compromised Windows systems, sold by initial access brokers. Ransomware groups frequently purchase this access rather than compromising systems themselves.
- Corporate email access: Compromised business email accounts, particularly valuable for BEC attacks and as a starting point for network intrusion.
How Dark Web Monitoring Works
Dark web monitoring services use a combination of automated crawlers, human intelligence researchers, and access to databases of known breach data to monitor for mentions of your organisation's domain, email addresses, and other identifiers on dark web forums and marketplaces.
When a match is found — for example, an employee's work email address appears in a newly posted credential dump — the monitoring service generates an alert. Reputable services (such as those integrated into Microsoft Defender or offered through platforms like Huntress or ID Agent) provide the specific email address, the source of the breach, and whether a plaintext password is included.
A Real-World Scenario
A marketing manager at a Gold Coast accounting firm used the same password for their work Microsoft 365 account and their personal fitness app account. The fitness app suffered a data breach and posted the credentials to a dark web forum. Without dark web monitoring, this went undetected. An attacker purchased the credential dump, attempted the email and password against Microsoft 365, and — because MFA wasn't enforced for that user — gained access to the mailbox. They spent two weeks reading emails before inserting themselves into a supplier payment thread and redirecting $47,000 to a fraudulent account.
With dark web monitoring, the firm would have received an alert within days of the credential dump being posted. The password would have been reset, MFA enforced, and the entire attack chain broken before it began.
Why Credential Stuffing Is So Effective
Credential stuffing attacks use automated tools to test stolen username/password combinations against hundreds of services at high speed. Because password reuse is extremely common, a significant percentage of tested credentials will work against at least one service. The defence against credential stuffing is twofold: strong, unique passwords for every account (managed via a password manager) and MFA, which renders a stolen password alone insufficient to log in.
Key Takeaways
- Staff credentials can appear in dark web dumps from breaches of completely unrelated services if they reuse passwords — your own systems don't need to be compromised.
- Dark web monitoring provides early warning that credentials have been exposed, enabling password resets before attackers can exploit them.
- MFA is the most effective defence against credential stuffing — stolen passwords alone cannot bypass a properly configured MFA requirement.
- A password manager enables unique passwords for every account, eliminating the credential reuse vulnerability that makes stuffing attacks so successful.