Dark Web Monitoring: Find Your Stolen Credentials First

Most intrusions do not start with an exploit. They start with a login that works. Somebody's username and password turn up in a file being passed around, an attacker tries them against your email tenant or your VPN, and the front door opens without a single alarm going off. Nothing was hacked, in the sense most people mean the word. Someone simply signed in.
Credential monitoring — often marketed as dark web monitoring — is the practice of watching for your organisation's usernames and passwords appearing in places they should not be, so that you find out before the person who bought them does. It is a genuinely useful control, and it is also one of the most oversold ones in the industry. Understanding both halves of that is what makes it worth paying for.
How corporate credentials end up for sale
Leaked business credentials do not have to come from a breach of the business itself. They arrive by more mundane routes.
- Third-party breaches. A staff member registers for a supplier portal, a conference, a design tool or a shopping site using their work email address. That service is breached years later and the whole user table is dumped. The work address goes with it, along with whatever password was chosen at the time.
- Combo lists. Criminals aggregate dozens of historic breaches into single deduplicated files of email-and-password pairs, then use them for credential stuffing at scale. Your address may appear in a combo list without any specific breach that you would recognise by name.
- Infostealer malware. A family member installs a cracked application on a home PC that is also used to check work email. The malware harvests every password saved in the browser, along with cookies and session tokens, and packages it as a "log" for sale. This is the most dangerous category, because the credentials are current and often come bundled with a live session.
- Phishing kits. Credentials typed into a convincing lookalike sign-in page are captured in real time and either used immediately or resold.
- Password reuse. One leaked password becomes five compromised systems the moment a person has used it for their laptop, the accounting package and the firewall's admin console.
What a monitoring service actually watches
A credential monitoring service continuously matches your domains against sources where stolen data circulates: breach corpora assembled from historic incidents, combo lists, paste sites, criminal marketplaces and forums, infostealer log dumps, and the messaging channels where those logs are advertised. Good services also cover variations you might forget — old domains you still receive mail on, mail aliases, and the personal addresses of executives where those are used for business correspondence.
When there is a match, a useful alert tells you which address was exposed, which source or breach it came from, roughly when it was first observed, and whether the password appeared in plaintext, as a hash, or not at all.
What it cannot see
This is where honesty matters more than marketing. There is no index of "the dark web" and no service scans all of it.
Monitoring cannot see data that was never traded publicly — the breach brokered privately to one buyer, or the credentials an attacker is keeping to themselves for a targeted campaign. It lags the original compromise, often by a long way, because data is typically monetised through private sales before it reaches the open lists. It cannot tell you whether a leaked password still works, whether the account has since had multi-factor authentication added, or whether anyone has actually tried it.
Most importantly: a clean report is not evidence that nothing has leaked. It means nothing has surfaced in the sources being watched. Treat credential monitoring as a detection layer that occasionally hands you an early warning, not as an assurance that your identities are safe.
"Found in a breach" is a signal, not a verdict
A hit is not automatically an incident, and treating every match as a five-alarm event burns out the people who have to respond.
Combo lists are full of recycled junk: addresses that never existed, passwords from a decade ago, and records copied between lists so many times that the original source is unknowable. A match against a breach that predates your current password policy, with a hash nobody has cracked, is a low-priority item. A match from a recent infostealer log, with a plaintext password that matches your current complexity rules, against an account that also shows an unfamiliar sign-in, is an incident.
What raises the priority is recency, plaintext exposure, privileged accounts, and correlation with anything unusual in your sign-in logs. Assess the match rather than reacting to it — but never file it away unactioned, because the cost of the assessment is small and the cost of being wrong is a mailbox takeover.
The response playbook when a credential surfaces
The value of monitoring is entirely in what happens in the hour after the alert. That should be a written, repeatable sequence rather than an improvisation.
- Force a password reset on the affected account, and make sure the replacement is genuinely new rather than the old one with a number incremented on the end.
- Revoke active sessions and refresh tokens. This is the step most often skipped, and it is the one that matters most. A password change does not evict an attacker who is already holding a valid session token — they stay signed in until the token is explicitly invalidated.
- Check registered authentication methods. Attackers who get in quietly enrol their own second factor, add an authenticator app or register a phone number. If a method appeared that the user does not recognise, remove it and treat the account as compromised.
- Audit reuse. Ask where else that password was used: the VPN, remote desktop, the accounting system, a shared administrative login, a personal account tied to a recovery address. One exposure often means several resets.
- Look for what has already happened. Inspect mailbox rules, forwarding addresses, new mailbox delegates and consented OAuth applications. Persistence is usually established early in an intrusion, and a hidden forwarding rule is the classic precursor to an invoice-redirection fraud — the pattern covered in more detail in what actually goes wrong with business email.
- Record the assessment. If there is reason to believe personal information was accessed, POPIA's security compromise obligations are engaged, and the written record of what you found and when you found it is what makes that notification defensible later.
Running that sequence consistently, at whatever hour the alert lands, is an operational commitment rather than a technical one. It is one of the practical reasons businesses fold identity monitoring into a managed IT and security arrangement instead of leaving it as a mailbox somebody checks on Mondays.
Monitoring only pays off when the password stops being enough
Here is the part that determines whether any of this is worth the subscription. A leaked password is only dangerous if a password is sufficient to sign in.
If your accounts are protected by phishing-resistant authentication, a credential appearing in a breach dump is a housekeeping task. If they are protected by a password alone, or by SMS codes, or by a push notification the user will approve out of habit, that same credential is a working key. Monitoring buys you time; strong authentication is what you spend the time on.
That is why credential monitoring should never be sold as a standalone product. It belongs alongside origin-bound authentication, conditional access, sensible session lifetimes and logging that will actually support an investigation. The reasoning behind moving off weak second factors is set out in the guide to MFA fatigue and phishing-resistant authentication.
Making it operational rather than decorative
A monitoring service that produces a monthly PDF nobody opens has no security value. To be worth having, it needs domain coverage that includes aliases and legacy domains, alerts routed into the same queue as your other security detections, a named owner for the response playbook, and reporting that shows the trend — which departments keep appearing, whether reuse is falling, and how quickly matches were closed out.
We treat credential exposure as one input among many rather than a product in its own right, correlated with endpoint and identity telemetry so that an exposed password and an odd sign-in are seen as one event instead of two unrelated tickets. If you would like a view of what is already circulating for your domain, and an honest assessment of what would happen if someone used it, that is part of what our cybersecurity services cover.
Frequently asked questions
Does dark web monitoring mean you are searching the dark web live?
No, and any provider claiming to is overstating it. Monitoring matches your domains against collected breach data, combo lists, infostealer logs and marketplace listings that have been gathered and indexed. It is a search of known circulating data, not a live crawl of everything criminals hold.
One of our staff addresses shows up in an old breach. Is that urgent?
Usually not, but it still needs closing out. Check whether the exposed password resembles anything currently in use, confirm the account has a strong second factor registered, and confirm no unfamiliar authentication methods or mailbox rules exist. If the exposure is recent, includes a plaintext password, or belongs to a privileged account, escalate it immediately.
We have multi-factor authentication everywhere. Do we still need this?
It becomes less critical, but it remains useful. Credential exposure tells you about password reuse habits, about staff registering work addresses on unrelated services, and about infostealer infections on devices that touch your data — and infostealer logs can include session cookies that bypass multi-factor authentication entirely.
This article is general information, not legal advice. POPIA decisions, correspondence with the Information Regulator and enforcement responses should be taken with a South African admitted attorney, and accountability rests with your Information Officer.
How does this relate to POPIA?
POPIA requires reasonable technical and organisational measures to protect personal information, and evidence that you detect and respond to compromises is part of demonstrating that. If an exposed credential leads to unauthorised access to personal information, that is a security compromise with notification duties attached, and your monitoring and response records are the basis of the investigation.
Want this handled for you?
Talk to the F1 team about cybersecurity, AI and managed IT for your business.




