Cyber security

Your email address is on the dark web. Does it matter?

Usually it means an old breach at some company you once had an account with, not that somebody is inside your systems today. What matters is whether the password that leaked is still in use anywhere, and whether multi-factor authentication would make it useless if it is.

Usually it means that a company you once had an account with was breached, sometimes years ago, and the list of email addresses and passwords from it has been copied around ever since. It does not mean somebody is in your systems, and on its own it is not an emergency.

What actually decides whether it matters is two things. Whether the password that leaked is still in use anywhere today, and whether multi-factor authentication is switched on so that having the password is not enough.

What is the dark web, in plain terms?

A part of the internet that ordinary search engines do not index and that you reach with specific software. Some of what is there is legitimate, a lot of it is not, and the part that matters to a business is the marketplaces and forums where stolen credentials get traded.

The picture people have of somebody in a dark room hunting for your company by name is mostly wrong. Credentials from breaches are traded in enormous lists, cheaply, and the buyers run them automatically against everything to see what still works. Nobody is choosing you. You are in the list because a hotel booking site or a forum you signed up to in 2016 got breached.

That is not reassuring, exactly, but it changes what you should do about it.

Should you panic when you get the alert?

No, and it is worth understanding why the alerts arrive with such urgency attached.

Credential monitoring is easy to sell because the finding is guaranteed. Run any established business domain through a breach dataset and something will come back, because after twenty years online everybody has an address in some list somewhere. An alert saying your details have been found on the dark web is close to a certainty rather than a discovery, and it is often the opening of a sales conversation rather than an incident.

That does not make monitoring worthless. It makes it an early warning rather than a control, and worth exactly what an early warning is worth: something, as long as you have already done the things it is warning you about.

What should you actually do about it?

In this order.

  1. Find out what leaked. Have I Been Pwned is free, run by a well known security researcher, and will tell you which breaches an address appears in and roughly what was taken. Our breach checker uses the same data and adds what to do about each one, in plain English. Checking a domain rather than a single address needs verification that you own it, which is a sensible thing for them to require.
  2. Change the password anywhere it is still in use. The breach itself is old news. The password being reused on your email or your accounting system is the live problem.
  3. Switch multi-factor authentication on everywhere it is not already. This is the control that makes the whole question much less interesting, because a leaked password on its own stops being enough to get in.
  4. Get a password manager in place, so that "is this password used anywhere else" has an answer rather than a shrug. We put NordPass in for clients, which also scans for the credentials in your vault turning up in breach data, so the warning and the fix are in the same place.
  5. Watch for the sign in attempts. If credentials for your domain are circulating, you will see failed sign ins from places nobody in your business has been. That is worth having somebody looking at.

Is credential monitoring worth paying for?

It is worth having as a layer. It is not worth having instead of the layer underneath it.

The honest ranking, most useful first: multi-factor authentication on every account, unique passwords on the accounts that matter, somebody watching your sign in activity, and then monitoring for credentials appearing in breach data. The last one tells you about a fire. The first three are the reason the fire does not spread.

If somebody is selling you monitoring as the answer, and your business still has accounts without multi-factor authentication on them, the order is wrong and you are paying to be told about a risk you could have removed.

We use NordPass with our clients, and the reason is the order above rather than the alerting. It is a password manager first, which is the control: every account gets its own password, and changing one no longer means wondering what else it unlocks. The breach scanning comes attached to it, so the alert arrives in the same place as the fix. That is a much more useful arrangement than a monitoring product that tells you about a problem and then leaves you to go and find every account that shares the password.

NordPass documents the feature as its Data Breach Scanner.

Where this connects to everything else

The reason leaked credentials matter at all is what happens next. Somebody with a working password and no second factor gets into a mailbox, sets up a rule to hide the replies, and reads the email traffic until there is a payment worth diverting. That is the mechanism behind Friday afternoon fraud and behind most of the invoice fraud that hits small businesses.

Removing the value of a leaked password is therefore not really about the dark web at all. It is about making sure that a password on its own opens nothing.

If you want somebody to check where your business currently stands, get in touch and ask. That means looking at which accounts have multi-factor authentication and which do not, whether anyone would notice a suspicious sign in, and whether any of the addresses in your business are turning up in breach data. What we run day to day is on the cyber security page, and what it costs is on the pricing page.

Questions

The questions people ask us about this

Can we get our data removed from the dark web?

No, and anybody offering to do it for a fee is selling you something that cannot be delivered. Once a set of credentials has been copied and traded, there is no central place to delete it from.

What you can do is make the credentials worthless, which is the point of changing the password and switching multi-factor authentication on.

We got an email saying they have our passwords and a video of us. Is it real?

Almost never. That is a mass mailed extortion attempt, and the password quoted is usually an old one from a public breach, included to make it convincing. Do not pay, do not reply, and change the password if it is still in use anywhere.

How do we know if a password was reused?

You mostly cannot, which is why a password manager is worth the small amount of effort. It is the only practical way to know that each account has its own password and to change one without wondering what else it unlocks.

Read next

Cyber security

Why are phishing attempts getting better, and what stops them working?

Because the attacks are bought off a shelf now rather than built. Phishing kits are sold as a subscription, complete with convincing fake login pages and a dashboard showing how many people fell for it, so the skill barrier has gone. What stops them is multi factor authentication on everything, filtering that catches what Microsoft misses, and staff who have been given permission to be slow.

Read this

Cyber security

Will your cyber insurance actually pay out?

Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.