TL;DR:
- Dark web monitoring checks whether your email addresses and passwords have appeared in known data breaches and criminal marketplaces
- Free tools like Have I Been Pwned cover most small businesses’ needs — paid business tools add real-time alerts and domain-level monitoring
- An alert means you need to change the affected password immediately and check for unauthorised access — not panic, but act quickly
When a service you use gets hacked, your credentials often end up in breach databases traded on dark web forums and marketplaces. These credentials get sold, combined with data from other breaches, and used in “credential stuffing” attacks — automated login attempts across hundreds of services. Dark web monitoring is the process of checking whether your business’s email addresses and passwords have appeared in these databases, giving you a chance to act before attackers do.
What Dark Web Monitoring Actually Checks
Good monitoring services scan:
- Known breach databases: Lists of username/password combinations from breached services (LinkedIn, Adobe, Dropbox, and thousands of others)
- Paste sites: Sites like Pastebin and Ghostbin where hackers publish stolen credential dumps
- Criminal marketplaces: Forums and markets on the dark web where credentials and stolen data are traded
- Stealer logs: Data exfiltrated by infostealer malware, which often includes passwords, cookies, and form data from infected computers
What they don’t typically detect in real time is active targeting of your specific business — that’s the domain of threat intelligence services far beyond SMB budgets.
Free Tools Worth Using
Have I Been Pwned (HIBP)
haveibeenpwned.com is the gold standard free resource, maintained by security researcher Troy Hunt. Enter any email address to see which breaches it appears in. The Domain Search feature lets you search all addresses at your domain at once — essential for businesses.
HIBP Notifications (free): register your domain to receive email alerts whenever any address at your domain appears in a new breach. This is the most important free tool available and every small business should set it up today.
The Pwned Passwords API checks specific passwords against 847 million+ compromised passwords without revealing the password to the service — built into most good password managers.
Google One / Google Account
If your business uses Gmail or Google Workspace, Google’s built-in dark web monitoring (via Google One) checks your email address against breach databases and sends alerts through your Google account dashboard.
Password Managers with Breach Monitoring
If you’re using a business password manager (which you should be), breach monitoring is likely already included:
- 1Password: Watchtower feature checks all stored credentials against HIBP on an ongoing basis and flags compromised passwords in your vault
- Bitwarden: Exposed Passwords report checks vault credentials against HIBP; available on free and paid plans
- Dashlane: Dark web monitoring is a flagship feature — checks email addresses against breach databases and alerts in the app
The advantage of password manager integration is contextual: when a breach alert fires, you can see exactly which account is affected and change the password in one click.
Business-Focused Monitoring Services
For businesses wanting more comprehensive monitoring beyond just email/password checks:
Flare (~£30–80/month): Monitors dark web forums, Telegram channels, paste sites, and breach databases for your domain, business name, employee emails, and company data. Aimed at SMBs. Includes alerts when your data appears in stealer log marketplaces.
SpyCloud (business pricing): Focuses on account takeover prevention. Partners with many enterprise password managers and security platforms.
Mozilla Monitor Plus (~£8/month individual): Upgraded version of Firefox Monitor with ongoing monitoring and data removal requests from data broker sites.
For most small businesses with under 20 staff, HIBP domain notifications plus a password manager’s built-in breach monitoring covers 90% of what paid services offer, at no additional cost.
What to Do When You Get an Alert
Step 1: Don’t panic — but do act within 24 hours
An alert means your credentials appeared in a breach database. It doesn’t necessarily mean your account has been accessed. You have a window to get ahead of any attackers.
Step 2: Identify the affected account
The alert will tell you which email address appeared in which breach. Check whether you have an account with that service — the breach may be years old.
Step 3: Change the password immediately
Change the password for the affected service. If you use (or used) the same password anywhere else, change it there too. This is why password reuse is so dangerous — one breach compromises every account with the same password.
Step 4: Enable multi-factor authentication
If the service supports MFA and you haven’t enabled it, do it now. Even if your password is compromised, MFA prevents login without the second factor.
Step 5: Check for unauthorised access
Review login history for the affected account. Look for unfamiliar locations, devices, or access times. Most services (Google, Microsoft 365, Dropbox) have an “active sessions” or “login history” view.
Step 6: Report to your team
If the breach involves a work account, let your IT contact or whoever manages security know. Multiple staff members using the same compromised service should all change passwords.
NCSC Guidance
The UK National Cyber Security Centre recommends using HIBP’s domain search as part of routine security hygiene checks. The NCSC’s free Early Warning service also provides notifications about vulnerabilities and threats affecting your IP address ranges — worth registering alongside HIBP monitoring.
The Bottom Line
Dark web monitoring doesn’t prevent breaches — it tells you about them faster. The value is in the response time: acting within hours of a credential appearing in a breach database is far better than discovering an account compromise weeks later when damage has already been done.
Start with HIBP domain notifications (free, five minutes to set up) and your existing password manager’s breach detection. That combination is genuinely effective and costs nothing.