Dark web
The dark web is the part of the internet that is only reachable through an anonymising network such as Tor, where both the visitor and the server can stay unidentified. For a security team it matters as a marketplace: it is where stolen credentials, network access and data taken from organisations are traded and published.
How it works
Ordinary web traffic reveals who is talking to whom. An anonymity network breaks that link by relaying each connection through several independent nodes with layered encryption, so no single relay knows both ends. Tor is the most used of these, and its onion services extend the same property to the server: a site can be reachable without its operator’s address being known.
That is the entire technical basis. It is a transport property, not a separate internet. The content served over it is ordinary web content, and the anonymity applies equally to a whistleblower, a journalist working under a hostile government, and a criminal marketplace. Conflating the transport with the crime is the mistake that makes most coverage of the topic useless.
What concerns a security team is a specific set of venues. Marketplaces selling stolen credentials and access. Forums where initial access brokers advertise a foothold in a specific organisation, usually described by sector, country and revenue rather than by name. Leak sites operated by extortion crews, which publish stolen data on a countdown to force payment. And bulk dumps of infostealer logs, which are credentials and session cookies harvested from infected machines and which are the most operationally dangerous of the four, because they are current and labelled with the exact service each credential belongs to.
Much of this now also lives on messaging platforms and on ordinary websites, which is worth saying plainly: the criminal economy is not confined to onion services, and monitoring that only looks there is looking at part of it.
What goes wrong
The first misunderstanding is scale. The dark web is small. The vast majority of what people mean when they say it is a handful of forums and marketplaces, and monitoring is therefore not a boil-the-ocean problem, it is a question of access and of language.
The second is what an appearance means. Finding a credential belonging to your organisation in a combined list does not tell you when it was taken, whether it is current, or which service it belongs to. Old corpora are recombined and resold constantly, and treating every hit as a live incident produces alert fatigue that ends with nobody reading the reports. Infostealer logs are the exception: those come with a timestamp, a machine, and the exact URL, and they should be treated as urgent because they usually include the session cookies as well.
The third is timing. Where an organisation learns it is on a leak site, the intrusion happened weeks earlier and the negotiation has already failed. Monitoring is an early warning about the last stage, not about the first. It is genuinely useful, and it is not detection.
The fourth is what we are careful never to do, and it is worth being explicit about because the market around this is full of claims that do not survive scrutiny. We do not publish counts of listings, sizes of marketplaces or growth rates, because those numbers cannot be verified independently and every published figure we have traced back has come from a vendor with a product to sell. What we report to a client is what was found for them, where, and when.
Dark web, deep web and surface web
These three are used interchangeably in the press and they describe different things. Only one of them is about anonymity.
| Surface web | Deep web | Dark web | |
|---|---|---|---|
| What it is | Pages a search engine has indexed | Anything not indexed | Sites reachable only through an anonymity network |
| Typical content | Public websites | Webmail, banking sessions, intranets, databases behind a login | Onion services, of every kind |
| How you reach it | A normal browser | A normal browser, plus credentials | A client for that network |
| Relative size | The smallest of the three | By far the largest | Very small |
| Anonymity | None by default | None by default | The defining property |
| Is it inherently criminal? | No | No | No, though it hosts criminal venues |
The row that corrects the common error is the fourth. Your webmail is in the deep web. So is every page behind a login, every internal application, and every database query result. That is most of the internet by volume, and it has nothing to do with anonymity networks. Describing the deep web as a dangerous underworld, which is standard in general press coverage, describes ordinary authenticated web use.
Common mistakes
Treating every credential hit as an incident. Without a date and a source, a hit from a recombined corpus tells you a password existed once. Prioritise infostealer logs, which are dated and current.
Buying monitoring as prevention. It reports what has already happened elsewhere. It is worth having as early warning, and it changes nothing about your controls.
Believing vendor size and volume figures. They are unverifiable. Ask any supplier what their claims are measured from, and treat the answer as the product demonstration.
Ignoring access broker listings. A listing describing your sector, country and revenue band, with the type of access on offer, is a specific warning that somebody already has a foothold.
Sending staff to look. Investigating these venues safely requires isolated infrastructure, an operational security discipline and often language skills. Improvised research puts the researcher and the organisation at risk.
How to reduce the exposure
Most of what appears about an organisation gets there through two routes, and both are addressable. Credentials arrive because a user reused a corporate password on a consumer service, or because a machine with a browser session on it was infected. Access is offered because a remote entry point had no origin-bound second factor.
So the controls that reduce your presence in these venues are not exotic. Enforce multi-factor authentication on every path, including the ones that were exempted. Check passwords against breached-credential corpora at the point they are set. Reduce the value of a stolen session by binding it to a device. And when a credential does appear, reset it and revoke the sessions, since resetting the password alone leaves a stolen cookie working.
For the data-exposure half, the useful work is knowing what would hurt if published and where it lives, which is data classification applied for a practical reason rather than for a policy document.
Where monitoring is in place, define in advance what each category of finding triggers. A credential hit from an old corpus is a password reset. An infostealer log is an incident with a device investigation attached. A listing offering access to your organisation is an immediate review of every remote entry point.
Where this shows up in an audit
An engagement that includes this work delivers what was found, with the source, the date and an assessment of whether it is current, and it says which findings could not be dated. That distinction is the honest part of the deliverable, because an undated hit is not actionable in the same way.
Where credentials are found, we correlate them against the client’s own directory to establish which accounts are live and which paths accept them today, and that correlation is what turns a list into a work item. Where access is being advertised, we treat it as a lead for testing the entry points named, not as a confirmed breach, and we say so.
We do not report volumes, trends or market sizes, and we do not use them in proposals. What can be evidenced is what was found for this client, on this date, at this source.
Continuous observation of these venues for a specific organisation is what monitoring criminal marketplaces on your behalf provides, and it is early warning rather than a control.
FAQ
Is the dark web illegal? No. It is a transport mechanism with legitimate uses including journalism, research and circumventing censorship. Some of what is hosted on it is criminal, which is a statement about content and not about the network.
What is the difference between the deep web and the dark web? The deep web is everything a search engine has not indexed, which includes your webmail and every internal application, and it is most of the internet. The dark web is the much smaller set of sites reachable only through an anonymity network.
Our data appeared on a leak site. What does that mean? That an extortion operation took data from your organisation and published it because payment was not made or negotiation stalled. The intrusion happened earlier, so the immediate work is establishing how they got in, alongside the notification obligations that publication triggers.
Is dark web monitoring worth paying for? As early warning, yes, particularly for infostealer logs where the credentials are current and the session cookies come with them. It is not a security control and it does not prevent anything, so it should be bought as intelligence and judged on what it finds for you specifically.