This isn't fearmongering — it's statistics. Here's what the dark web actually is, how credentials end up there, and what your business can do about it right now.
Here's a number worth sitting with: as of 2026, there are more than 15 billion stolen username and password combinations circulating on dark web marketplaces and hacker forums. That's roughly two exposed credentials for every person on the planet.
Those credentials didn't all come from giant corporations. A huge chunk came from third-party services — the project management tool your team uses, the HR software you signed up for three years ago, the e-commerce platform your employees used their work email to register on. They signed up with their work email address, reused a password they also use to log into your systems, and now that combination is sitting in a database someone is selling for $10.
We check this routinely for new clients. The results are almost never zero. Usually we find anywhere from a handful to dozens of compromised credentials tied to their company's domain. Most business owners had no idea. Their employees had no idea. And those accounts were still active, still using the same passwords, still logging in to company systems every day.
Let's walk through what's actually happening, why it matters, and — most importantly — what you can do about it today.
The "dark web" sounds like something out of a thriller movie, but it's simpler than the media makes it seem. The regular internet — the websites you access through Chrome or Safari — is the "surface web." There's also a layer called the "deep web," which is just content not indexed by search engines: your email inbox, your bank's internal pages, private databases. Totally normal stuff.
The dark web is a specific part of the internet that requires special software to access, most commonly a browser called Tor. Tor routes traffic through a series of encrypted relays to anonymize who's connecting and from where. That anonymity makes it useful for legitimate purposes — journalists in authoritarian countries, privacy advocates, researchers — but it also makes it a convenient place to run marketplaces that wouldn't survive on the regular internet.
Those marketplaces include places where people buy and sell stolen data. Login credentials. Credit card numbers. Social Security numbers. Access to compromised business systems. All of it.
You don't need to access the dark web yourself to be affected by it. Your credentials can end up there without you ever knowing, and attackers can use them to try to log in to your systems from anywhere in the world.
The path from your employees' passwords to a dark web marketplace usually goes one of a few ways.
This is the most common one. A service your employees use — LinkedIn, Adobe, Dropbox, a payroll platform, any number of smaller SaaS tools — gets breached. The attacker steals the user database, which includes email addresses and (hopefully encrypted, but often not well-encrypted) passwords. That database gets posted on a hacker forum or sold on a marketplace. Anyone who used their work email to sign up for that service is now in the pile.
The kicker is password reuse. If your employee used the same password for their LinkedIn account that they use to log into your company systems, the attacker doesn't need to hack you directly. They just try the stolen credentials against your systems. This technique is called "credential stuffing," and it's automated — attackers can try thousands of combinations per hour.
Phishing emails that successfully steal credentials don't just disappear. Attackers collect them, verify which ones work, and sell the working ones. A credential that gives access to a Microsoft 365 account sells for more than one that doesn't, because it opens doors to email, SharePoint, Teams, and everything else in that tenant.
If an employee has an "infostealer" malware infection on their personal computer — and they use that computer for any work tasks — the malware can capture everything they type, including passwords. These logs get packaged up and sold in bulk. It doesn't matter how secure your business systems are if someone's harvesting keystrokes on the other end.
An employee signed up for a tool five years ago with their work email. The tool was acquired, neglected, and eventually breached. Nobody remembered the account existed. The password was the same one they still use for other things. Now it's out there.
We hear this a lot. The reasoning goes: "We're a 15-person landscaping company. Why would a hacker care about us?"
The answer is that attackers using dark web credentials aren't sitting at a keyboard manually trying to break into your business. They're running automated tools against millions of targets simultaneously. Your size doesn't matter. What matters is whether your credentials are in a database somewhere and whether you reuse passwords.
The attack isn't targeted. It's a sweep. They run credential stuffing attacks against common platforms — Microsoft 365, Google Workspace, QuickBooks Online, banking portals — and they take what they can get. A successful login to a small business's Microsoft 365 tenant can be worth thousands of dollars if the attacker finds the right opportunity: a business email compromise scam, a ransomware deployment, or selling access to another attacker.
Small businesses also tend to have weaker controls than large enterprises — less monitoring, no dedicated security team, looser password policies. That makes them easier to actually exploit once access is obtained, which makes the credentials more valuable, not less.
If you want to understand the full scope of how your business could be targeted, our Cybersecurity Essentials Guide covers the threat landscape in plain English.
Before you can fix anything, you need to know what you're dealing with. Here's how to start.
Troy Hunt's Have I Been Pwned (haveibeenpwned.com) is a free, legitimate service that lets you check whether an email address appears in known data breaches. Type in your work email and any personal emails your employees use for work-related accounts. The site will tell you which breaches your address appeared in and what type of data was exposed.
There's also a domain search feature. If you enter your company's domain (e.g., yourcompany.com), it will show you all the email addresses from your domain that appear in breach databases. You'll need to verify ownership, but it takes about five minutes and the results are eye-opening. You can also sign up for notifications when new breaches affect your domain — this is free and highly recommended.
If you're running Microsoft 365 Business Premium, you have access to Microsoft Entra ID Protection, which monitors for risky sign-ins and compromised credentials. Under the Microsoft Entra admin center, look for "Identity Protection" — it will flag user accounts where Microsoft has detected the credentials in a known breach. This is automated and ongoing, which is exactly what you want.
If you're on a lower M365 tier, this feature may not be included. Check your M365 security settings to understand what you have access to.
For businesses that want ongoing, comprehensive monitoring, there are dedicated services that scan dark web forums and marketplaces for credentials tied to your domain. These go deeper than Have I Been Pwned — they monitor sources that aren't in publicly released breach databases, including private forums and newly posted dumps. Many managed IT providers, including us, include this as part of a security package.
Finding compromised credentials isn't a disaster. It's information. Here's what to do with it.
Any account associated with a compromised email address needs a new, unique password immediately. Don't ask employees to get to it when they have time. Make it happen today. In Microsoft 365, an admin can require a password reset at next login for any user. Do it.
The new password should be long, random, and unique to that account. Which brings us to the next step.
The root cause of most credential exposure risk is password reuse. People reuse passwords because remembering twenty different strong passwords is genuinely hard. A password manager solves that problem — it generates and stores unique, strong passwords for every account, and employees only need to remember one master password.
If your business doesn't have a password manager yet, this is the time. We covered the whole picture in our post on why your business needs a password manager. Business-grade options like Bitwarden Teams, 1Password Business, or Dashlane Business let you manage credentials centrally, share passwords securely between team members, and revoke access when someone leaves.
This is the single most effective control against stolen credentials. Even if an attacker has a correct username and password, MFA stops them cold — they can't get in without the second factor, which only the real user has.
If you're on Microsoft 365 and MFA isn't enabled for all users, stop reading and go enable it right now. The setup takes about 20 minutes. It stops over 99% of automated account compromise attacks. We've written a full breakdown of how to roll out MFA without driving your team crazy.
Go through your company's software subscriptions and identify any services where employees registered with their work email. Anything that's no longer actively used should be closed. Less exposure surface means fewer credentials out there tied to your domain. This is also good practice when employees leave — their accounts on every service need to be deactivated, not just their main company login.
Our guide on IT documentation covers how to build an account inventory you can actually maintain over time.
Here's the thing about dark web monitoring: breaches happen constantly. The LinkedIn breach from years ago is still out there. But there will also be a breach next month at some service you're using today, and credentials from that will be for sale within weeks. One-time checks don't stay current.
An ongoing monitoring approach looks like this:
None of this requires a full-time security team. It requires process and the right tools, most of which you either already have or can get inexpensively.
The combination of MFA, a password manager, and active monitoring closes the door on the vast majority of credential-based attacks. These three things won't prevent every breach, but they'll stop the automated, low-effort attacks that make up most of the threat landscape for small businesses.
If you have or are considering cyber liability insurance, many insurers are now requiring basic controls like MFA and documented credential management practices as a condition of coverage. Having compromised credentials on the dark web and no monitoring in place could affect both your ability to get coverage and how a claim would be handled in a breach event. That's worth knowing before something happens.
You don't need to overhaul everything at once. Here's a practical starting point:
Day 1: Go to haveibeenpwned.com and run a domain search on your company's email domain. See what comes back.
Day 2–3: For any compromised accounts, force a password reset. Do not wait.
This week: If MFA isn't enabled on Microsoft 365 or Google Workspace, turn it on. This is the highest-leverage security action available to you.
This month: Evaluate a business password manager and start rolling it out. Bitwarden Teams starts at a few dollars per user per month. The protection it provides is worth it many times over.
Ongoing: Sign up for domain notifications on Have I Been Pwned, or ask your IT provider about comprehensive dark web monitoring as part of your security program.
Finding your credentials on the dark web feels alarming. But it's fixable — and knowing about it puts you in a far better position than the businesses who don't find out until someone's already in their systems.