Know What Has Already Leaked
Dark Web Monitoring
Credentials, documents and customer data leave organisations every day and end up for sale or shared for free. We watch the places that trade in them for anything tied to your domains and brand, validate every hit by hand, and tell you exactly what to reset, rotate and contain.
See the engagement path, 6 phasesSee the full Managed Services service index
Overview
Dark web monitoring watches criminal marketplaces, forums, paste sites and closed messaging channels for leaked credentials, documents and data connected to your domains and brand. An analyst validates each hit before it reaches you, so what arrives is a confirmed exposure with response guidance rather than another feed to triage, and we make takedown and removal requests for leaked data, impersonating domains and fake profiles where a host or platform will accept one. It runs either continuously as a managed service or as scheduled sweeps with a report each cycle, decided at scoping. It answers a different question from attack surface management: not what you expose, but what has already left your control.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Dark Web Monitoring engagement, 6 phases in order, each one selectable. Phase 1, Scope, Identifiers and Authorisation. We agree what identifies you, because everything after this is matched against that list. Monitoring the wrong identifiers produces noise, and monitoring an identifier that is not yours is not ours to do. Activities: Confirm the domains, email domains, brands and product names in scope; Record the executive and role identities you want watched; Agree what is out of scope, including personal accounts and third-party brands; Capture written authorisation to monitor on your behalf. Hands over Agreed Monitoring Scope and Identifier List. Phase 2, Source Coverage and Collection. We read the places leaked data actually changes hands and match what appears there against your identifiers. We state which kinds of source are covered and do not claim to see everything. Activities: Match identifiers against marketplace and criminal forum listings; Watch paste sites and public code and file shares for leaked material; Follow closed messaging channels that trade in credentials and documents; Track newly registered look-alike domains and impersonating profiles. Hands over Raw Exposure Candidates. Phase 3, Analyst Validation and Triage. An analyst confirms every candidate before it becomes an alert. Aggregated breach lists recycle the same records for years, so validation is what separates an exposure from an echo. Activities: Confirm each record is genuinely tied to an in-scope identifier; Attribute the record to a breach or leak and judge whether it is current; Discard recycled, duplicate and already-reported entries; Rate the exposure by the access it would give an attacker. Hands over Validated Exposure Findings. Phase 4, Notification and Response Guidance. You receive the confirmed finding, the evidence behind it and what to do about it. The guidance names accounts and credentials rather than telling you to improve your posture. Activities: Notify your named contact with the affected account and the evidence; Specify the password resets required and their order; Identify the tokens, API keys and session credentials to rotate; Recommend containment or closer watch for the affected accounts. Hands over Exposure Notification with Response Actions. Phase 5, Takedown and Removal Requests. Where leaked data, an impersonating domain or a fake profile sits with a host, registrar or platform that accepts abuse reports, we prepare, submit and chase the request. The outcome belongs to them, so we report progress rather than promise removal. Activities: Assemble the evidence pack the host or platform requires; Submit and track requests for leaked data and impersonating domains; Report fake profiles and accounts to the platforms hosting them; Record the status of every request, including the refusals. Hands over Takedown Request Record and Status. Phase 6, Reporting and Rotation Re-check. Each period you get a report of what is new, what recurred and what closed, plus a re-check that the credentials we flagged were actually rotated. A finding is closed when it has been changed, not when it has been read. Activities: Report new, recurring and closed exposures against the last period; Re-check flagged credentials to confirm they were rotated; Highlight repeat exposure patterns such as password reuse across teams; Hand findings that indicate a live compromise into incident response. Hands over Periodic Exposure Report and Rotation Re-check. Each phase begins from the artefact the phase before it produced.
Phase 01 Scope, Identifiers and Authorisation
We agree what identifies you, because everything after this is matched against that list. Monitoring the wrong identifiers produces noise, and monitoring an identifier that is not yours is not ours to do.
What Happens In This Phase
- Confirm the domains, email domains, brands and product names in scope
- Record the executive and role identities you want watched
- Agree what is out of scope, including personal accounts and third-party brands
- Capture written authorisation to monitor on your behalf
The Handover
Agreed Monitoring Scope and Identifier List
The next phase starts from this.
Phase 01 Scope, Identifiers and Authorisation
We agree what identifies you, because everything after this is matched against that list. Monitoring the wrong identifiers produces noise, and monitoring an identifier that is not yours is not ours to do.
What Happens In This Phase
- Confirm the domains, email domains, brands and product names in scope
- Record the executive and role identities you want watched
- Agree what is out of scope, including personal accounts and third-party brands
- Capture written authorisation to monitor on your behalf
The Handover
Agreed Monitoring Scope and Identifier List
The next phase starts from this.
- 01
Scope, Identifiers and Authorisation
We agree what identifies you, because everything after this is matched against that list. Monitoring the wrong identifiers produces noise, and monitoring an identifier that is not yours is not ours to do.
OutputAgreed Monitoring Scope and Identifier ListActivities
- Confirm the domains, email domains, brands and product names in scope
- Record the executive and role identities you want watched
- Agree what is out of scope, including personal accounts and third-party brands
- Capture written authorisation to monitor on your behalf
- 02
Source Coverage and Collection
We read the places leaked data actually changes hands and match what appears there against your identifiers. We state which kinds of source are covered and do not claim to see everything.
OutputRaw Exposure CandidatesActivities
- Match identifiers against marketplace and criminal forum listings
- Watch paste sites and public code and file shares for leaked material
- Follow closed messaging channels that trade in credentials and documents
- Track newly registered look-alike domains and impersonating profiles
- 03
Analyst Validation and Triage
An analyst confirms every candidate before it becomes an alert. Aggregated breach lists recycle the same records for years, so validation is what separates an exposure from an echo.
OutputValidated Exposure FindingsActivities
- Confirm each record is genuinely tied to an in-scope identifier
- Attribute the record to a breach or leak and judge whether it is current
- Discard recycled, duplicate and already-reported entries
- Rate the exposure by the access it would give an attacker
- 04
Notification and Response Guidance
You receive the confirmed finding, the evidence behind it and what to do about it. The guidance names accounts and credentials rather than telling you to improve your posture.
OutputExposure Notification with Response ActionsActivities
- Notify your named contact with the affected account and the evidence
- Specify the password resets required and their order
- Identify the tokens, API keys and session credentials to rotate
- Recommend containment or closer watch for the affected accounts
- 05
Takedown and Removal Requests
Where leaked data, an impersonating domain or a fake profile sits with a host, registrar or platform that accepts abuse reports, we prepare, submit and chase the request. The outcome belongs to them, so we report progress rather than promise removal.
OutputTakedown Request Record and StatusActivities
- Assemble the evidence pack the host or platform requires
- Submit and track requests for leaked data and impersonating domains
- Report fake profiles and accounts to the platforms hosting them
- Record the status of every request, including the refusals
- 06
Reporting and Rotation Re-check
Each period you get a report of what is new, what recurred and what closed, plus a re-check that the credentials we flagged were actually rotated. A finding is closed when it has been changed, not when it has been read.
OutputPeriodic Exposure Report and Rotation Re-checkActivities
- Report new, recurring and closed exposures against the last period
- Re-check flagged credentials to confirm they were rotated
- Highlight repeat exposure patterns such as password reuse across teams
- Hand findings that indicate a live compromise into incident response
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Dark Web Monitoring scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Criminal marketplace and forum collections, Breach and combination-list corpora, Paste and public file-share monitors, Closed messaging channel feeds, Look-alike domain registration watch, Analyst case and evidence tracker, Takedown and abuse-report channels. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST CSF 2.0 DE.CM and ID.RA, ISO/IEC 27001:2022 Annex A 5.7 and 5.24, MITRE ATT&CK Credential Access (TA0006), the DPDP Act.
What We Run
7 tools
- Criminal marketplace and forum collections
- Breach and combination-list corpora
- Paste and public file-share monitors
- Closed messaging channel feeds
- Look-alike domain registration watch
- Analyst case and evidence tracker
- Takedown and abuse-report channels
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
4 standards
- NIST CSF 2.0 DE.CM and ID.RA
- ISO/IEC 27001:2022 Annex A 5.7 and 5.24
- MITRE ATT&CK Credential Access (TA0006)
- DPDPIndiaAct
Deliverables
What You Receive
- Validated exposure findings with the evidence behind each one
- Response guidance naming the resets, rotations and containment required
- Takedown requests for leaked data, look-alike domains and fake profiles
- Periodic report of new, recurring and closed exposures
- Rotation re-check confirming flagged credentials were changed
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What do you actually monitor, and what is outside this service?
We monitor criminal marketplaces, forums, paste sites and closed messaging channels, including Telegram, for leaked credentials, documents and data tied to the domains and brands you put in scope. That means employee and customer credentials appearing in breach dumps and combination lists, internal documents offered for sale or shared for free, and impersonating domains and fake profiles trading on your name. We are equally clear about the limits. Nobody sees all of the dark web: it is a shifting set of private, invite-only and short-lived places, so we report what our sources can reach and say so, rather than claiming complete coverage. We do not buy data from criminals, we do not access your systems during monitoring, and we do not name the commercial sources we read. Discovery of what you expose on the public internet is a different service, attack surface management, which runs alongside this one.
What happens when credentials of ours turn up?
An analyst validates the hit before it reaches you. Most raw matches are recycled: the same credential appears across dozens of aggregated lists for years, so an unfiltered feed produces alarm without information. We confirm the record is genuinely tied to your domain, work out which breach or leak it came from and whether the password is current, and discard what is stale or already reported. What you then receive is the account affected, the evidence behind the finding and specific response guidance: which passwords to reset, which tokens, API keys and session credentials to rotate, and which accounts to contain or watch while you do it. Where the exposure suggests a wider compromise, we say what else to check, and if you run SOC as a service with us the finding goes to the same analysts who watch your alerts. We do not change anything in your environment ourselves.
Can leaked data actually be removed?
Sometimes, and we make the requests, but nobody can promise it. Where data, an impersonating domain or a fake profile sits with a host, registrar, platform or paste site that answers abuse reports, we prepare and submit the takedown request with the evidence it needs, and we chase it. What we will not do is tell you when, or that they will, because the decision belongs to the host and not to us, and the criminal side of the internet has no abuse desk at all. Be clear-eyed about what that means: once a credential or document has spread across mirrors, archives and private collections, it cannot be unpublished. Monitoring tells you what is exposed so you can make it worthless, which is why the response guidance matters more than the removal request. A rotated password in a leaked list is a historical record rather than a live risk.
How is this different from attack surface management?
They look at opposite sides of the same problem. Attack surface management looks outward at infrastructure: the domains, subdomains, IP ranges, cloud-exposed services and certificates you present to the public internet, and the misconfigurations on them. Dark web monitoring looks at information that has already left your control and is circulating somewhere it should not be: credentials, documents, customer data, and people passing themselves off as you. Neither finds what the other finds. An estate can be well configured and still have a finance team's passwords for sale, and a clean credential picture says nothing about the forgotten staging host nobody registered. The two also resolve differently. An exposure is fixed by changing a configuration; a leak is answered by rotation, containment and, where possible, a removal request. Clients often run both, and we deliberately kept them separate services so neither claims the other's coverage.
Does this run continuously, or in cycles?
Either, and we decide it at scoping. Run as a managed service, collection and matching are continuous and a validated finding reaches you as soon as an analyst has confirmed it, with a report summarising each period. Run as scheduled sweeps, we search the same sources on an agreed cadence, typically monthly or quarterly, and you get a report at the end of every cycle. The choice is about how fast an exposure would hurt you and how much handling you want, not about quality: the same sources are read and the same validation is applied either way. Continuous suits organisations with large workforces, consumer logins or frequent credential reuse. Periodic sweeps suit smaller estates, and organisations that want the evidence for an audit or a board on a predictable rhythm. We state the cadence, the sources in scope and what is excluded in writing before the service starts.
What do you need from us to start?
Less than most services. We need the identifiers that define you: your domains and email domains, brand and product names, the executive names you want watched, and any customer-facing domains that are yours but not obvious. We need written authorisation to monitor on your behalf, and a named contact who can act on a finding at short notice, because a validated credential leak is only useful if somebody can reset an account. It helps to know which systems matter most and whether single sign-on covers them, so response guidance names the right place to rotate. We do not need access to your network, your directory or your mail, and monitoring does not touch your systems. Scoping usually takes a call and a written scope; the first sweep follows, and the first report is the most crowded one you will get, because it covers everything already circulating.
Keep Moving Through Managed Services
Service 4 of 9 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong