Book an Appointment

Dark Web Monitoring as an Early Warning System

How to detect compromised credentials, mentions of your company and data leaks before attackers exploit them – and where the limits of the approach lie.

Stolen credentials are a commodity today: infostealer malware harvests them at scale from infected devices, initial access brokers refine them into ready-made network access, ransomware groups buy in. Dark web monitoring watches the sources of this underground economy – forums, marketplaces, Telegram channels, leak sites – and raises an alert when data related to your own company surfaces there. Used correctly, it creates a window of time between data exfiltration and exploitation in which an incident can still be prevented. This article explains how the underground market works, what monitoring can realistically deliver, what a robust response process looks like, and how the approach fits into NIS2 and DORA.

The Essentials at a Glance

01

The underground economy: infostealers, access brokers, leak sites

The criminal market is organised around division of labour. Infostealer malware exfiltrates credentials, session cookies and browser data from infected devices and bundles them into so-called stealer logs, which are traded on marketplaces and in Telegram channels; combolists aggregate email-password combinations from old and new leaks, and the leak sites of ransomware groups publish stolen data sets. Initial access brokers (IABs) turn such raw data into verified network access and sell it on – according to ENISA, with a trend towards low-priced, high-volume offerings in which the majority of accesses trade for under roughly 2,800 euros. The market is also remarkably resilient: after the takedown of the RedLine and META infostealers (Operation Magnus, October 2024), use of the Lumma stealer rose by more than 350 percent between the first and second half of 2024; ENISA continues to assess infostealers as a fixed link in the cybercriminal supply chain.

02

Why early detection matters: the pipeline to ransomware

There is a measurable amount of time between data exfiltration and attack – and that window is exactly what monitoring addresses. According to the Verizon Data Breach Investigations Report 2026, 73 percent of the ransomware victims examined showed an infostealer or credential-leak event in the year before the attack; for half of those affected, the event occurred within 95 days before the attack. The BSI's 2025 report on the state of IT security in Germany underlines the connection as well: 72 percent of ransomware attacks reported in Germany were accompanied by data leaks, and both the number of leak victims and the number of credential thefts increased. Whoever detects compromised credentials before they are exploited can break the attack chain at its first link – at far lower effort than in incident response.

03

What dark web monitoring realistically finds

In practice, monitoring services deliver three classes of hits. First, compromised credentials of employees and customers from stealer logs, breach databases and combolists – often together with session cookies, the affected login URLs (such as VPN portals, SSO or admin interfaces) and details of the infected device. Second, mentions of the company in forums, on marketplaces and in Telegram channels, for example access offers from initial access brokers or discussions about planned attacks. Third, leaked data sets and documents on leak and paste sites, for instance following an incident at a service provider. What is typically monitored for this purpose are the organisation's own domains including subdomains, email addresses, IP ranges, and brand and product keywords. Only what surfaces in accessible sources becomes visible – exclusive direct sales between criminals naturally remain hidden.

04

Response process: from hit to action

A hit is initially just a data point – triage is what makes it actionable. It starts with verification (does the data set actually concern your own company, is the password still valid?) and prioritisation by account type and exposed service: privileged accounts and VPN and SSO access before non-critical portal logins. The standard playbook covers password resets, invalidation of active sessions and tokens, checking or enforcing multi-factor authentication, analysing affected systems for suspicious logins, and searching for the source of the leak, such as an infected endpoint or a third-party provider. If the assessment reveals a significant security incident or a personal data breach, reporting obligations apply: under NIS2 Art. 23, the early warning within 24 hours, the incident notification within 72 hours and the final report no later than one month after the notification; under GDPR Art. 33, notification to the supervisory authority without undue delay and, where feasible, within 72 hours. Monitoring alerts therefore belong firmly integrated into the existing incident response process.

05

Limits and false positives

Without context, dark web monitoring generates a lot of noise. Combolists recycle old leaks, so many hits concern passwords changed long ago or employees who have since left; private accounts registered with a company email address say little about the security of the corporate network, and similar-looking domains lead to false attributions. No provider can guarantee completeness – closed forums and private sales escape observation. The approach is also inherently reactive: whatever is found has already been exfiltrated, and there is no reliable way to "delete" it from circulation. Without a defined triage and response process, raw hits therefore mainly produce alert fatigue. The meaningful measure of success is not the number of hits, but the time from detection to effective action.

06

Where it fits: a threat intelligence building block under NIS2 and DORA

Neither NIS2 nor DORA requires dark web monitoring by name – but it contributes to concrete obligations. NIS2 (Directive (EU) 2022/2555) requires in Art. 21(2), among other things, policies on risk analysis (point (a)) and incident handling (point (b)); company-specific threat data from underground sources provides solid evidence for these. DORA (Regulation (EU) 2022/2554, applicable since 17 January 2025) explicitly obliges financial entities in Art. 13(1) to maintain capabilities and staff to gather information on vulnerabilities and cyber threats and to analyse their likely impact; threat-led penetration testing (TLPT, Art. 26) likewise builds on threat analyses. Dark web monitoring is thus an operational building block of cyber threat intelligence – complementing external attack surface management, vulnerability management and SOC detection, not replacing them.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ENISA · 2025

ENISA Threat Landscape 2025

Analyses infostealers as a fixed link in the cybercriminal supply chain, price trends among initial access brokers, and takedowns such as Operation Magnus (reporting period 07/2024–06/2025).

Verizon · 2026

2026 Data Breach Investigations Report

Documents the infostealer-to-ransomware pipeline: 73% of ransomware victims with a preceding infostealer or credential-leak event, half of them within 95 days before the attack.

BSI · 2025

Die Lage der IT-Sicherheit in Deutschland 2025

Documents, for the reporting period 07/2024–06/2025, a growing number of leak victims and credential thefts; 72 percent of reported ransomware attacks were accompanied by data leaks.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2) with the risk management measures (including risk analysis and incident handling) and Art. 23 with the reporting deadlines of 24 hours/72 hours/one month.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Art. 13(1) obliges financial entities to gather information on vulnerabilities and cyber threats; Art. 26 governs TLPT; applicable since 17 January 2025.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 33 requires notification of personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours.

Do you know what is circulating about your company?

VamiSec offers dark web monitoring as a managed service together with our partner Paranoid Lab – from detection through triage to guided response. Contact us for a no-obligation initial consultation.