Right now, some of your staff's business email addresses - and possibly their passwords - are likely available for purchase on dark web marketplaces. They were exposed in a breach of a third-party service your staff used, sometimes years ago. Here's what dark web monitoring is, what it can and can't do, and what action to take.
How Business Credentials End Up on the Dark Web
The dark web is not accessed through a regular browser - it's a part of the internet that requires specific software and is home to a significant criminal economy, including marketplaces where stolen credentials are bought and sold.
Credentials end up there through data breaches. When a website or service is hacked - LinkedIn, Adobe, Canva, a payroll provider, a supplier portal, or any of thousands of other services - the stolen user database (containing email addresses and hashed or plaintext passwords) is typically sold to or shared with other criminals within days.
If one of your staff members registered for that service using their work email address - even if it was years ago at a previous employer - that credential is now potentially in criminal hands. If they reused the same password on business systems, attackers will try it.
What Dark Web Monitoring Actually Does
Dark web monitoring services continuously scan known criminal forums, paste sites, and credential marketplaces for your organisation's email domain. When they find credentials associated with your domain - for example, jane@yourcompany.com.au paired with a password - they alert you.
What you receive is typically:
- The email address found in the breach
- The source of the breach (which service was hacked)
- The date the breach occurred or was discovered
- Whether the password was exposed in plaintext or as a hash
This gives you the information to act before attackers do.
What Dark Web Monitoring Cannot Do
It's important to be clear about the limitations:
- It doesn't prevent breaches - it detects credentials that are already exposed
- Coverage isn't complete - not all stolen data makes it to monitored marketplaces. Private sales and closed forums may not be captured.
- It's reactive, not preventive - by the time you're alerted, the credential has already been available to criminals for some period of time
Dark web monitoring is a useful early warning system, not a replacement for strong passwords and MFA.
What to Do When Your Credentials Are Found
If a dark web monitoring alert shows that a staff member's business email and password have been exposed:
- Change the password immediately - on any system where that password was used
- Check for reuse - ask the staff member whether they used that password on business systems (Microsoft 365, banking, accounting software). If yes, change it on those systems immediately.
- Enable MFA if not already active - this is the most effective control against credential stuffing. Even a stolen password is useless without the second factor.
- Check for suspicious activity - review login history on Microsoft 365 or Google Workspace for unexpected sign-ins from unusual locations or times
- Notify your IT provider - they can review access logs and confirm no unauthorised access has occurred
How Perth Businesses Can Check Right Now
The free tool Have I Been Pwned (haveibeenpwned.com) allows you to check whether an email address has appeared in known public data breaches. You can check individual staff emails or, for a business, set up domain monitoring that alerts you when any address on your domain appears in a new breach. This is a free starting point before investing in a commercial monitoring service.
Commercial dark web monitoring services go further - they access more data sources, provide more detail, and integrate with managed IT platforms for automated alerting. These are typically provided as part of a managed IT or managed security service.
Why MFA Makes Dark Web Findings Far Less Dangerous
The single most effective response to the dark web credential threat is multi-factor authentication. If every account in your business has MFA enabled, a stolen password is largely useless to an attacker - they still need the second factor. For Perth businesses that haven't yet enabled MFA across Microsoft 365 or Google Workspace, this is the highest-priority action to take today.
Frequently Asked Questions
How would our staff's work email end up on the dark web?
Usually through a breach of an unrelated third-party service, LinkedIn, Canva, a supplier portal, that a staff member signed up to using their work email, sometimes years ago at a previous employer. Once that service is hacked, the stolen credentials are typically sold on to other criminals within days.
Can dark web monitoring actually prevent a breach?
Not on its own, it's a detection tool, not a prevention tool, it tells you when credentials have already been exposed rather than stopping the exposure happening. It's a useful early warning system that works best alongside strong passwords and MFA, not as a replacement for either.
Is there a free way to check if our business has been exposed?
Yes, Have I Been Pwned (haveibeenpwned.com) lets you check individual email addresses for free and can set up domain-wide monitoring that alerts you to new breaches. It's a good starting point before considering a paid commercial monitoring service with broader coverage.
What should we do the moment a dark web alert comes through?
Change the exposed password immediately, check whether it was reused anywhere else in the business and change it there too, and confirm MFA is enabled on the affected account. Reviewing recent sign-in activity for anything unusual is also worth doing straight away.
Dark web monitoring and MFA enforcement are both included as standard in our cybersecurity services for Perth businesses.
Cybersecurity Services →Want to know if your Perth business credentials are on the dark web?
Call 0433 087 091 - we can run a dark web scan on your business domain and tell you exactly what's been exposed.
Book a Free Dark Web ScanFor related reading, see our guides to Cybersecurity Checklist for Perth Small Businesses and EDR vs Antivirus: What Perth Businesses Need to Know.