Short answer

List your company domains and key email addresses, then run them through reputable, lawful breach-intelligence platforms — the same sources security teams use. Don't browse the dark web yourself. It's unsafe, you can't verify what you find, and continuous monitoring will catch far more than a one-off look ever could.

"The dark web" sounds like a place you visit. For a business, it's more useful to think of it as a marketplace — a sprawling, constantly-refreshed set of forums and shops where stolen data is bought, sold and swapped. Your company doesn't have to be hacked directly to end up there. Most of the time, it isn't.

How your data gets there without you being "hacked"

There are three common routes, and none of them require an attacker to breach your systems directly:

Third-party breaches

A service you use — a supplier, a SaaS platform, an old online account a staff member signed up for with their work email — gets breached. Their leak now contains your people's work email addresses and, very often, the passwords they used there. If anyone reused that password on your systems, the attacker now has a working key.

Infostealer malware and "stealer logs"

An employee's device picks up infostealer malware — usually from a dodgy download or a convincing phishing lure. It quietly harvests everything the browser has saved: passwords, active sessions, cookies, autofill. That bundle, a stealer log, is sold in bulk. This is now one of the most common ways business credentials leak, and the company itself was never "breached" at all.

Credential dumps and combolists

Billions of leaked username-and-password pairs are compiled into searchable lists and traded freely. Attackers spray them at business logins — email, VPN, banking portals — betting on reuse. It's cheap, automated, and it works often enough to be worth their time.

The uncomfortable part: most businesses that have data on the dark web have no idea. There's no alert, no ransom note — just your credentials sitting in someone's dataset, waiting for a quiet Tuesday when it's convenient to use them.

Why you should not go looking yourself

It's tempting to want to "just go check." Don't. Accessing dark-web marketplaces directly exposes your device to malware and scams, carries real legal risk, and — crucially — you can't reliably verify anything you find or safely act on it. Legitimate dark-web monitoring is never done by engaging criminals or buying stolen data. It's done through established breach-intelligence platforms that lawfully index leaks, dumps and stealer logs, so you get the signal without the exposure.

How to check safely — the practical steps

  1. Inventory what to watch. Your primary domains, key mailboxes (especially executives, finance and admin), and any legacy domains still in use.
  2. Run them against lawful breach-intelligence. Reputable platforms will tell you which addresses appear in known breaches and stealer logs, and often what type of data was exposed.
  3. Prioritise the dangerous hits. A leaked marketing newsletter signup is noise. A finance manager's email and password appearing in a recent stealer log is an emergency.
  4. Reset and harden. Change exposed credentials, kill active sessions, and turn on multi-factor authentication everywhere — MFA neutralises most reused-password attacks outright.
  5. Monitor continuously. A one-off scan is a photo; your exposure is a live feed. New leaks surface every week, so the real protection is an alert the moment something new appears.

If you find something: treat it as an incident, not an IT ticket

Once you've contained the immediate risk, check the affected accounts for actual misuse — logins from odd locations, forwarding rules you didn't set, payment details changed. And if the exposed data includes personal information, this is now a POPIA matter: the Act requires you to notify the Information Regulator and the affected people as soon as reasonably possible. The middle of a live exposure is the wrong time to improvise that process — which is exactly what a breach-response plan is for.

Continuous monitoring changes the whole posture. Instead of discovering a leak when a client's account is drained or a regulator calls, you get told the day your data appears — while there's still time to reset a password and close the door quietly.

Find out what's already out there — for free.

We'll run a no-obligation exposure report against lawful breach-intelligence for your domain, show you what's surfaced, and tell you honestly whether continuous monitoring is worth it for your business.