Short answer
List your company domains and key email addresses, then run them through reputable, lawful breach-intelligence platforms — the same sources security teams use. Don't browse the dark web yourself. It's unsafe, you can't verify what you find, and continuous monitoring will catch far more than a one-off look ever could.
"The dark web" sounds like a place you visit. For a business, it's more useful to think of it as a marketplace — a sprawling, constantly-refreshed set of forums and shops where stolen data is bought, sold and swapped. Your company doesn't have to be hacked directly to end up there. Most of the time, it isn't.
How your data gets there without you being "hacked"
There are three common routes, and none of them require an attacker to breach your systems directly:
Third-party breaches
A service you use — a supplier, a SaaS platform, an old online account a staff member signed up for with their work email — gets breached. Their leak now contains your people's work email addresses and, very often, the passwords they used there. If anyone reused that password on your systems, the attacker now has a working key.
Infostealer malware and "stealer logs"
An employee's device picks up infostealer malware — usually from a dodgy download or a convincing phishing lure. It quietly harvests everything the browser has saved: passwords, active sessions, cookies, autofill. That bundle, a stealer log, is sold in bulk. This is now one of the most common ways business credentials leak, and the company itself was never "breached" at all.
Credential dumps and combolists
Billions of leaked username-and-password pairs are compiled into searchable lists and traded freely. Attackers spray them at business logins — email, VPN, banking portals — betting on reuse. It's cheap, automated, and it works often enough to be worth their time.
Why you should not go looking yourself
It's tempting to want to "just go check." Don't. Accessing dark-web marketplaces directly exposes your device to malware and scams, carries real legal risk, and — crucially — you can't reliably verify anything you find or safely act on it. Legitimate dark-web monitoring is never done by engaging criminals or buying stolen data. It's done through established breach-intelligence platforms that lawfully index leaks, dumps and stealer logs, so you get the signal without the exposure.
How to check safely — the practical steps
- Inventory what to watch. Your primary domains, key mailboxes (especially executives, finance and admin), and any legacy domains still in use.
- Run them against lawful breach-intelligence. Reputable platforms will tell you which addresses appear in known breaches and stealer logs, and often what type of data was exposed.
- Prioritise the dangerous hits. A leaked marketing newsletter signup is noise. A finance manager's email and password appearing in a recent stealer log is an emergency.
- Reset and harden. Change exposed credentials, kill active sessions, and turn on multi-factor authentication everywhere — MFA neutralises most reused-password attacks outright.
- Monitor continuously. A one-off scan is a photo; your exposure is a live feed. New leaks surface every week, so the real protection is an alert the moment something new appears.
If you find something: treat it as an incident, not an IT ticket
Once you've contained the immediate risk, check the affected accounts for actual misuse — logins from odd locations, forwarding rules you didn't set, payment details changed. And if the exposed data includes personal information, this is now a POPIA matter: the Act requires you to notify the Information Regulator and the affected people as soon as reasonably possible. The middle of a live exposure is the wrong time to improvise that process — which is exactly what a breach-response plan is for.
Continuous monitoring changes the whole posture. Instead of discovering a leak when a client's account is drained or a regulator calls, you get told the day your data appears — while there's still time to reset a password and close the door quietly.
How to protect your company from dark-web exposure
You can't pull data back once it's being traded — but you can make sure very little of yours ever gets there, and that you're the first to know if it does. Seven practical moves, in rough order of impact:
Layer your defences
No single tool catches everything. A layered stack — endpoint protection, email security, firewall and backups — stops most attacks before they ever reach your data.
Train your people
Most breaches start with a person, not a server. A short, practical awareness habit — spotting phishing, handling data — is the cheapest defence you have.
Kill password reuse
One reused password is one breach away from an open door. Enforce unique passwords, a password manager, and multi-factor authentication everywhere.
Patch relentlessly
Attackers exploit known holes a patch already fixed. Update software and devices on a schedule — not "when someone remembers".
Don't work unprotected on public wifi
Coffee-shop and hotel networks are trivial to snoop. Staff handling sensitive data should connect through secure remote access, always encrypted.
Monitor the dark web
The point isn't to browse it — it's to be told the day your data appears. Continuous monitoring turns a silent leak into an early warning.
Have a breach plan ready
The middle of an incident is the wrong time to improvise. A rehearsed breach-response plan — including POPIA's 72-hour clock — turns panic into procedure.
Frequently asked questions
How do I check if my business is on the dark web?
List your company domains and key email addresses, then run them through reputable, lawful breach-intelligence platforms that index known leaks, credential dumps and infostealer logs. Do not browse the dark web yourself — it is unsafe and unnecessary. The safest option is continuous monitoring that alerts you the moment your data surfaces.
Is it legal or safe to search the dark web myself?
Accessing dark-web marketplaces yourself exposes you to malware, scams and legal risk, and you cannot reliably verify what you find. Legitimate dark-web monitoring is done through established breach-intelligence services that collect leaked data lawfully — never by engaging criminals or buying stolen data.
What is a stealer log?
A stealer log is the package of data harvested from a device infected with infostealer malware — saved passwords, browser sessions, cookies and autofill details. These logs are traded in bulk and are one of the most common ways business credentials end up for sale, even when the company itself was never breached.
What should I do if my business data is leaked?
Reset the exposed credentials immediately, enforce multi-factor authentication, and check the affected accounts for misuse. If personal information is involved, POPIA requires you to notify the Information Regulator and affected people as soon as reasonably possible — treat it as a formal incident, not just an IT fix.