"Your email was found on the dark web" is one of the more alarming alerts a security app can show, and the phrase is often used to sell protection products. This guide explains, calmly, what the dark web actually is, why most people who use the technology behind it are not criminals, how stolen personal data ends up being traded, what dark web monitoring really checks, and what to do if an alert names your details. It draws on the Tor Project, the Electronic Frontier Foundation, the Center for Internet Security, US and European law enforcement announcements and consumer guidance from the FTC and the UK's National Cyber Security Centre. It does not explain how to find or use any illegal marketplace, and you do not need to visit the dark web to protect yourself.
Surface web, deep web and dark web
The Center for Internet Security draws the lines clearly (CIS):
- The surface web is what you use every day: public pages "available to the general public using standard search engines."
- The deep web is "the portion of the web that is not indexed or searchable by ordinary search engines." Most of it is ordinary and private: your webmail inbox, online banking, medical portals and anything behind a login.
- The dark web is "a less accessible subset of the Deep Web" that "requires specialized software." In practice the best-known part is made of onion services reached through the Tor network.
So when people say "the dark web", they usually mean a small, deliberately hidden corner of the internet, not the huge private deep web that everyone already uses.
How Tor and onion services work, in brief
Tor grew out of "onion routing" research at the US Naval Research Laboratory. The Tor Project describes the idea as routing traffic "through multiple servers" and encrypting it at each step, and says the network today has "thousands of relays run by volunteers and millions of users worldwide" (Tor Project). The EFF sums up the effect: Tor masks "who you are and where you are connecting from," although anyone who can see your network activity can still see that you are using Tor.
Onion services go a step further and hide the server as well. The Tor Project lists their properties: the service's location and IP address are protected, traffic is encrypted from the visitor to the onion host, and the long, random-looking address is itself derived from the service's cryptographic key, which makes impersonation hard. Its own worked example is a local newspaper running an onion service through SecureDrop to receive anonymous tips (Tor Project).
Who uses it, and why
The EFF describes Tor as "a volunteer-run service that provides both privacy and anonymity online by masking who you are and where you are connecting from," and notes it can help people get around censorship (EFF Surveillance Self-Defense). The Tor Project points to its role for activists during the Arab Spring. CIS lists legitimate activities including "accessing information, sharing information, protecting one's identity, and communicating with others," and notes that "many news organizations operate on the Dark Web to protect confidential sources." The EFF is also candid about limits: browsing is slower, some sites do not work, only the Tor Browser itself is protected, and if you log in or enter personal details, "that website will be able to identify you."
In short, the technology is a privacy tool used by journalists, sources, activists and ordinary privacy-minded people. The same anonymity also attracts criminals, which is where the reputation comes from.
The criminal markets, and the people closing them
Marketplaces selling drugs, stolen data, forged documents and malware do operate on the dark web, and they are a constant target for law enforcement. The US Department of Justice says Nemesis Market sold illegal drugs and "criminal cyber-services, such as stolen financial information, fraudulent identification documents, counterfeit currencies, and computer malware," and was seized with German and Lithuanian authorities (US Department of Justice). In Operation RapTor, which drew on intelligence from US investigators and Europol's European Cybercrime Centre, police arrested 270 dark web vendors, buyers and administrators across ten countries and seized more than $200 million in currency and digital assets (US Department of Justice).
Stolen data is not only traded in hidden corners, though. When 14 countries acted against the LeakBase forum, the Justice Department described it as one of the world's largest forums for buying and selling stolen data, with hundreds of millions of account credentials, card numbers and bank details, and noted it was "available on the open web and in English" (US Department of Justice). For your own risk, where the data is traded matters less than the fact that it was stolen.
How your data ends up there
Almost always, it starts with someone else's security failure or a scam aimed at you:
- Data breaches: a company's systems are hacked and customer records copied. Have I Been Pwned, a free breach-lookup service, defines a breach as data "inadvertently exposed in a vulnerable system, usually due to insufficient access controls or security weaknesses" (Have I Been Pwned).
- Phishing: fake login pages and messages that collect passwords and card numbers directly.
- Malware: software on an infected device that captures saved passwords, cookies and card details.
- Skimming and physical theft: card skimmers, stolen post and wallets, as USA.gov describes.
Once collected, the data is used for account takeover (trying the same email and password on other sites), card fraud, opening new accounts in your name and more convincing phishing. The NCSC warns that criminals use breached details to make scam messages look genuine and may contact victims long after a breach is made public (NCSC).
What "dark web monitoring" actually checks
Identity theft services and some password managers advertise dark web monitoring. Typically the provider compares your details, such as email addresses, phone numbers, card numbers or ID numbers, against collections of leaked data gathered from breaches, criminal forums and paste sites. The FTC lists "websites that identity thieves use to trade stolen information" among the sources identity monitoring may check (FTC). Password managers do something narrower: 1Password's Watchtower, for example, flags saved logins for websites with a reported breach and passwords that have appeared in a breach (1Password).
Its limits are worth knowing:
- It can only report data that has surfaced somewhere the provider can see. Silence is not proof your data is safe.
- An alert usually arrives after the theft, sometimes long after. It tells you to act; it does not undo anything.
- It cannot remove your data. Once copied and traded, it cannot be recalled.
- Google retired its free dark web report, saying feedback showed it "didn't provide helpful next steps," and pointed users to its Security Checkup, Password Manager and Password Checkup tools instead.
That last point is a fair summary of the whole category: the value lies in the actions an alert prompts, so judge any monitoring product by the guidance and help that come with the alert.
What to do if an alert names your details
- Do not panic, and do not click links in the alert email itself. Open the app or website you already use. Scammers imitate breach notices; the NCSC advises contacting an affected organisation through its official website.
- Email address: on its own, expect more spam and phishing. Make sure the mailbox has a strong, unique password and two-step sign-in.
- Password: change it now on that site and on every other site where you used it. The NCSC suggests using a passkey instead where one is available. A password manager makes unique passwords practical.
- Card number: call the number on the back of the card, report it and ask for a replacement. Watch statements for small test charges.
- Social Security number or other ID number: freeze your credit with Equifax, Experian and TransUnion, which is free, consider a fraud alert, and in the US get an IRS Identity Protection PIN. The FTC's guidance on credit freezes and fraud alerts explains how (FTC).
- Check your accounts for logins, payments or changes you did not make, as the NCSC recommends, and report actual misuse at IdentityTheft.gov in the US or Report Fraud in the UK.
Do not go looking for yourself
It can be tempting to browse the dark web to see whether your details are for sale. Do not. You are unlikely to find a specific record among many hidden sites, some sites are themselves scams after your payment or log-in details, downloads can carry malware, and you risk landing on illegal material. Legitimate tools do the checking for you without any of that risk: a free breach lookup such as Have I Been Pwned, the breach alerts built into most password managers, and your bank's own fraud monitoring.
Free protection versus paid monitoring
Most of the protective steps cost nothing: unique passwords, two-step sign-in, credit freezes, reading statements. Paid identity services add continuous monitoring of more sources, recovery help and sometimes insurance; they suit people who want someone else to watch and help. If you are weighing those options, our identity theft protection comparison sets out what the main services include, and our password manager comparison covers the tools that make unique passwords and breach alerts easy.
The bottom line
The dark web is a privacy technology with a criminal fringe that police keep dismantling. Your exposure comes from breaches and scams, not from the dark web itself, and the defence is the same whether your data turns up there or on an open forum: unique passwords, two-step sign-in, a credit freeze, and quick action when an alert arrives.