Skip to content
How‑To Guides

Dark Web Monitoring: What It Does and Doesn’t Do

Dark web monitoring alerts you when your credentials appear in criminal marketplaces. Here is the essential guide covering free options, paid services, and response steps.

Dark Web Monitoring: What It Does and Doesn’t Do

The dark web — a collection of websites accessible only through the Tor network, intentionally not indexed by standard search engines — is where stolen credentials, personal data, payment cards, and identity information are traded after data breaches. By the time a breach becomes public news, the stolen data has often been circulating in these marketplaces for weeks or months already. For a broader walkthrough, our Complete Guide to Online Security and Privacy is a good next read.

Dark web monitoring services scan these marketplaces and forums continuously and alert you when information associated with your identity appears — giving you the earliest possible warning that your data has been compromised. The value is entirely in timing: a monitoring alert received the day stolen credentials appear means you can change the password before attackers have used it extensively. A breach notification received six months later means attackers have had six months of unobserved access.

What dark web monitoring scans and finds

Dark web monitoring services crawl forums, marketplaces, paste sites, and private channels where stolen data is bought, sold, and shared. The data most commonly found includes:

  • Email-password combinations from breached services
  • Financial account credentials
  • Payment card numbers with expiry and CVV
  • Government ID numbers (SSN, National Insurance numbers, passport numbers)
  • Medical record fragments
  • “Fullz” packages — complete identity profiles (name, address, SSN, DOB, financial data) sold for fraud purposes

What to do when a monitoring alert arrives:

  1. Identify which service the breach came from (if specified in the alert)
  2. Change the password for that service immediately using the password manager’s generator
  3. Check whether the same password was used elsewhere — change it on every matching service
  4. Enable two-factor authentication on the affected service if not already active
  5. If financial data was exposed: contact the card issuer to report possible fraud and request card replacement
  6. If government ID data (SSN) was exposed: report to the SSA and place a credit freeze at all three bureaus

Calibrating urgency from the alert: an alert specifying that passwords were exposed requires immediate response. An alert specifying only that the email address appeared (without associated password data) is less urgent — update the password for the specific service as a precaution, but it’s not a confirmed credential compromise requiring widespread password changes. Alert details typically specify which data categories were exposed; use this to determine the response level.

Free vs paid monitoring services

ServiceCostWhat it scansCoverage scope
Have I Been PwnedFreeEmail addressesPublic breaches only; 14+ billion records; email alerts on new breaches
Bitwarden Vault Health ReportsFree (email) / Premium $10/yr (full)Email addresses + saved credentialsPublic breaches via Have I Been Pwned integration
1Password WatchtowerIncluded in 1Password subscriptionSaved credentialsPublic breaches; also flags weak and reused passwords
Google Password CheckupFreeSaved Google passwordsPublic breaches; available at passwords.google.com
Aura / Identity Guard / LifeLock$10–30/monthEmail, phone, SSN, credit cards, addressesPrivate dark web marketplaces + public breaches
Credit card included benefitsFree (included)Varies by cardCheck the benefits portal for your specific card

The key distinction between free and paid services: Have I Been Pwned covers publicly disclosed breaches. Paid dark web monitoring services scan private dark web forums and marketplaces where fresh stolen data circulates before being publicly disclosed — this is where the early warning advantage is largest, since the median time between a breach occurring and its public disclosure is measured in months.

Monitoring built into services you already use

Before purchasing a separate dark web monitoring subscription, check whether you already have this monitoring available:

  • Password managers: Bitwarden Premium ($10/year) includes Vault Health Reports checking saved credentials against Have I Been Pwned. 1Password Watchtower performs the same function. These are particularly useful because they check actual saved credentials rather than just your email address — they alert you when a specific service you use has been breached and your stored credentials for that service are exposed.
  • Google Password Manager: passwords.google.com → Check Passwords → Password Checkup. Scans saved Google passwords against known breaches.
  • Apple iCloud Keychain: provides security recommendations for compromised passwords in Safari, visible in Settings → Passwords → Security Recommendations.
  • Microsoft Defender: includes credential monitoring for email addresses in Microsoft 365 Personal and Family subscriptions.
  • Premium credit cards: many cards — particularly American Express, Chase Sapphire, and Capital One premium cards — include identity monitoring benefits covering dark web monitoring for SSNs, email addresses, and payment card data. Check the benefits section of any premium card you hold; this monitoring may already be available and simply requires activation through the card’s benefit portal.

Our guide on protecting your personal data covers the upstream data minimisation practices that reduce exposure to the breaches dark web monitoring detects, and our guide on stopping data brokers covers the opt-out process for the aggregated profiles that monitoring services can’t remove. For current breach statistics and the latest findings from Have I Been Pwned’s database, Have I Been Pwned’s documentation covers how breach data is collected, what it contains, and how the notification system works.

Dark web monitoring limitations — what it can’t do

Dark web monitoring is a valuable early warning tool but has significant limitations worth understanding:

  • It doesn’t prevent breaches — it detects exposure after it’s already occurred. The password is already in criminal hands when the alert arrives. The alert improves your response time; it doesn’t reduce the initial compromise.
  • Coverage is never complete. No service monitors every dark web forum, marketplace, and private channel. Fresh data often circulates in private channels with extremely limited access before appearing on the more widely-monitored forums. The most valuable freshly-breached data may be sold in private transactions that monitoring services can’t reach.
  • False positives exist. Email addresses can appear in breach data for reasons that don’t represent a direct account compromise (newsletter lists, business cards, marketing databases). Not every alert represents a compromised account.
  • It doesn’t protect information that was never collected. The most effective protection against data appearing in dark web monitoring results is not providing the data in the first place — email aliases, VoIP numbers, and data minimisation practices reduce what attackers can find even after a breach.

Using monitoring alert trends as a signal

Over time, the pattern of monitoring alerts reveals useful information about overall data exposure trajectory. If the number of alerts for your email addresses is growing month over month, it indicates your email is appearing in an increasing number of fresh breach datasets — being more widely circulated in criminal databases.

Pivoting to email aliases more aggressively (as described in our guide on reducing your digital footprint) directly addresses this. Each alias creates a separate identifier for each service — a breach at one service exposes only that alias, not the primary email address that feeds the monitoring results.

Conversely: if monitoring alerts stabilise or decrease after implementing alias strategies and data broker opt-outs, the trend provides concrete evidence those upstream practices are working as intended. Dark web monitoring results are a lagging indicator of your data exposure posture — and watching the trend over months provides a useful feedback signal on whether privacy practices are reducing or maintaining your exposure level in practice, not just in theory.

Dark web monitoring for small businesses

For small businesses, a business email domain breach can mean employee credentials and customer data appearing in monitoring alerts — often before the breach is even discovered internally. Establishing breach monitoring on the business email domain through a service like SpyCloud or implementing individual monitoring for all employees provides a practical baseline without enterprise-level investment.

Leaked employee credentials are the most common initial access vector for corporate network compromises — an employee’s work email and reused password appearing in a breach database is a significant risk signal that dark web monitoring can surface before it’s exploited. For businesses that haven’t implemented this monitoring: Have I Been Pwned’s domain search (available at haveibeenpwned.com/DomainSearch for owners who can verify domain ownership) provides free monitoring for all email addresses on a domain, covering the entire organisation’s email exposure against public breach databases at no cost.

Dark web monitoring is most valuable as one layer in a broader security posture — combined with unique generated passwords (so breached credentials can be individually rotated without affecting others), two-factor authentication (so even a correctly breached password is insufficient for account access), and data minimisation (so less data enters circulation in the first place). The monitoring itself is the detection layer; the other controls are what limit the damage when monitoring sends an alert.

Setting up monitoring — the practical starting sequence

For users who haven’t yet set up any dark web monitoring:

  1. Register all your email addresses at haveibeenpwned.com for free breach notifications. This provides ongoing automatic alerts whenever those addresses appear in a newly-disclosed public breach. Takes five minutes; costs nothing; provides the most immediately actionable monitoring for most users.
  2. Enable the breach monitoring feature in your password manager. Bitwarden: Tools → Reports. 1Password: Watchtower. Run the check now to see any currently-flagged credentials, then set a reminder to run it monthly.
  3. Activate any monitoring benefits included with existing services (credit cards, identity monitoring through employer benefits, Microsoft or Google account monitoring). Check your credit card benefits portal specifically — premium cards often include monitoring that card holders never activate.
  4. Consider a paid service only if: your threat model includes government ID exposure, you’re concerned about private dark web marketplace coverage, or you’ve experienced identity theft and want comprehensive multi-identifier monitoring. For most individuals, steps 1–3 provide adequate coverage for the breaches most likely to affect them.

What “alert received” means in practice — a response sequence

A common scenario: you receive a Have I Been Pwned alert that your email address appeared in a breach at a service you don’t immediately recognise. The response: Our guide on Software Supply Chain Security covers an adjacent issue.

  • Check the breach date and what was exposed. Have I Been Pwned specifies when the breach occurred and what data categories were included. A breach from 2019 at a service you used once in 2018 is low urgency if you’ve already changed passwords since then.
  • Check whether you have an account at the breached service. Search your email inbox for registration or newsletter emails from that company name. Search your password manager for a saved login for that domain.
  • If you have an active account: log in and change the password immediately using your password manager’s generator. Enable 2FA if not active. If the breach included financial data: contact the card issuer.
  • If you don’t have an active account (or can’t remember having one): the email address was likely in a marketing list or newsletter database from that service. Low urgency — the main action is confirming your email password is unique (not shared with any service) so the harvested email address can’t be used for credential stuffing against your email account itself.
  • Check for reuse. Regardless of whether you recognise the service: run the password manager’s health report to check whether any current saved passwords were reused from the breached service. Update any that were.

Dark web monitoring done consistently — even just the free tier of Have I Been Pwned notifications combined with monthly password manager health reports — provides a meaningful improvement over discovering compromises through account lockouts or unexpected financial activity. The early warning is the value. Every hour between breach exposure and credential rotation is an hour during which the compromised credential can be used. Monitoring compresses that window as much as current technology allows. See also Biometric Data Privacy for a related case.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"