Dark Web
The dark web is the part of the internet reachable only through anonymizing networks like Tor, where stolen credentials and criminal services are traded.
The dark web is the portion of the internet that is only reachable through anonymizing overlay networks — most commonly Tor — and is not indexed by ordinary search engines. Anonymity has legitimate uses, from journalism to censorship circumvention, but for security teams the dark web matters chiefly as the marketplace layer of cybercrime: the place where the proceeds of a data breach are advertised, priced and resold.
How it works
Dark-web forums and markets operate like any e-commerce ecosystem, with vendors, escrow, reviews and reputation scores. The goods relevant to human risk are mostly stolen identity material: combo lists of emails and passwords assembled through credential harvesting and infostealer malware, session cookies that bypass MFA, corporate VPN accounts offered by initial access brokers, and full identity kits used for fraud. Alongside the goods sit the services — phishing kits, ransomware affiliate programs, bulletproof hosting, and social engineers for hire. A single employee's reused password can travel this economy for years: leaked in one breach, packaged into a combo list, tested against the corporate login, and finally sold as verified access. Much of the same trade now also happens in semi-private Telegram channels, so "dark web" is best understood as an economy rather than one specific network.
How to defend against it
You cannot take stolen data off the dark web, so defense means devaluing what is traded and reacting quickly when your organization appears in it. Dark-web monitoring — watching markets, forums and paste sites for your domains, executive names and credential dumps — turns the criminal supply chain into an early-warning feed: a mention that your access is for sale is a containment task for today, not a curiosity. Phishing-resistant authentication and a ban on password reuse make most credential listings worthless on arrival. Exposure findings also belong in your risk model — dark-web signals are one input into a human risk score, flagging which employees' credentials are circulating — and the response when something surfaces follows the standard sequence in our incident response guide: revoke sessions, reset credentials, then investigate how the material leaked.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo