What to do if your company details appear on the dark web

Company details can appear on the dark web following data breaches, credential theft and other security incidents, but their presence does not necessarily mean your business has been hacked. Exposed email addresses, passwords and account credentials can still create opportunities for phishing, account takeover, impersonation and further cyber attacks. This guide explains what it means when your company details are found on the dark web, the immediate steps you should take, and how to determine whether exposed credentials point to wider cybersecurity risks within your organisation.

A dark web alert is a warning sign

 

Discovering that your company’s details are available on the dark web can be worrying.

Perhaps a dark web scan has uncovered an employee’s email address and password. Maybe credentials associated with your company domain have appeared in data stolen from another organisation. Or perhaps information connected with one of your senior people is being circulated online.

The first thing to understand is that a dark web alert does not necessarily mean your company has been hacked.

But it does mean you should take it seriously.

For professional services businesses in particular, compromised credentials can give criminals a useful starting point for phishing, account takeover, impersonation and other attacks.

So what should you do next?

1. Understand exactly what has been exposed

 

Start by establishing what information has actually been discovered. There is a big difference between an old email address appearing in a historic data breach and a current company account appearing alongside a password that is still in use.

You need to understand:

  • Which email addresses or accounts are involved
  • What information has been exposed
  • When the information was compromised
  • Whether passwords or other credentials are included
  • Whether those credentials are still being used
  • Whether the same password has been reused elsewhere

This is why a dark web report should be treated as the beginning of an investigation rather than the end of one.

The important question isn’t simply “Are we on the dark web?

It’s “What risk does this create for our business?

2. Change compromised passwords immediately

 

If a password has been exposed and there is any possibility that it is still in use, change it. You should also check whether that password, or a variation of it, has been used for other accounts.

Password reuse is particularly dangerous because criminals can take credentials stolen from one service and automatically test them against Microsoft 365, email, cloud applications and other systems. One compromised password can therefore potentially become the key to several different doors.

Use strong, unique passwords and a secure password manager rather than relying on passwords people can easily remember and reuse.

3. Make sure Multi-Factor Authentication is enabled

 

Passwords alone are no longer enough to protect important business systems. Multi-factor authentication (MFA) adds another layer of verification before somebody can access an account.

That means a criminal who obtains a username and password can still be prevented from signing in. MFA should be enabled wherever possible, particularly for email, Microsoft 365, remote access, cloud applications and accounts with access to sensitive client or business information.

However, simply having MFA isn’t the whole answer. It needs to be configured correctly and supported by appropriate security policies.

4. Check whether the account has already been accessed

 

Changing a password closes one potential route into your systems but it doesn’t tell you whether somebody has already used it. Your IT or cybersecurity provider should investigate for signs of suspicious activity.

It may include unusual logins, unexpected locations, suspicious mailbox rules, unusual forwarding activity, changes to account permissions or other behaviour that doesn’t fit the user’s normal pattern. Receiving this information is important, particularly for professional services firms, and it can be accessed through Security Operations Centre (SOC) software.

Access to one person’s mailbox can give cybercriminals access to client data, invoices, transactions, colleague and supplier data. This information can then be used to create extremely convincing impersonation or payment fraud attacks.

IT for Professional Services

5. Warn the person involved

 

If an employee’s details have been exposed, tell them.

They need to know why their password in being changed and why they should be particularly cautious about unexpected emails, login prompts and authentication requests.

Cybercriminals frequently combined information from multiple sources. Knowing somebody’s name, company, email address, password or other personal information can make a phishing message considerably more believable.

Your people are an important part of your cyber defence, but only if they knew what to look out for.

6. Look beyond the individual compromised account

 

At this point, many organisations run the risk of thinking the problem is solved. They change the exposed password, enable MFA and move on. But an exposed credential should also prompt a bigger question:

What else don’t we know about our cyber risk?

For example:

  • Are other company credentials already circulating online?
  • Are employees reusing passwords?
  • Is MFA properly enforced across the business?
  • Are old or dormant accounts still active?
  • Are devices properly protected and monitored?
  • Are security updates being applied?
  • Can suspicious behaviour be detected quickly?
  • Would your team know what to do if an attack succeeded?

A dark web alert is one visible warning. Your objective should be to understand the wider picture.

7. Review the potential impact on clients and the business

 

For a law firm, accountancy practice or other professional services organisation, cybersecurity isn’t simply an IT issue. Your clients trust you with their information.

A compromised account could potentially expose confidential communications, financial information, personal data or commercially sensitive documents. In addition there can be contractual, regulatory, data protection or cyber insurance considerations, depending on what has happened.

If you find evidence that an account or system has indeed been compromised, the incident should be taken seriously.

What should you do next?

 

Finding company information on the dark web doesn’t automatically mean you have a serious security breach. But it does give you a reason to ask some important questions.

How did the information get there? Is it still current? Could somebody use it to access your systems? And, perhaps most importantly, is this an isolated issue or a sign that there are other security gaps you don’t know about?

The next step depends on what we’ve found and what you already know about your cybersecurity.

Start a conversation

 

If we’ve provided you with a dark web report, we’re happy to talk you through it.

We can explain what has been found, what it could mean for your organisation and whether there any immediate actions we would recommend.

You don’t need to be a cybersecurity expert and you don’t need to arrive with all the answers. The purpose of the conversation is simply to help you understand the findings and decide whether anything else needs investigating. From there, there are several possible next steps.

Book a call

Take our Cyber Assessment

 

If you’re not sure how well protected your organisation currently is, our Cybersecurity Assessment is a useful place to start. It helps you take a broader look at your cybersecurity rather than concentrating on one exposed password or email address.

The aim is to identify areas where you are already well protected, as well as possible security gaps that could warrant attention.

That gives us something much more useful to discuss. Instead of just

‘Have our details appeared on the dark web?’ but ‘How much confidence do our current security measures give us?’

Take the Cyber Assessment

Consider further security testing

 

Sometimes there is good reason to dig deeper.

For example, you may be concerned about vulnerabilities in your systems, have requirements from clients or insures, or simply want independent evidence of how your existing security measures will stand up to an attack.

In those circumstances, we may recommend further security testing, such as a penetration test.

A penetration test goes beyond answering questions about the security measures you have in place. It behaves like a hacker and actively tests systems for the weaknesses that can be exploited. It won’t be necessary in every situation, which is why we’d rather understand your circumstances first and recommend the appropriate next step.

The goal is confidence, not fear

 

A dark web report can be uncomfortable to receive, but its value is that it gives you information you can act on. Cybersecurity shouldn’t be about frightening businesses with everything that could possibly go wrong, it should be about knowing where you stand.

Do you understand your risks? Are sensible protections in place? Are there gaps that need attention? And if something did happen, could you detect it and rapidly respond to it?

For professional services organisations, being able to answer those questions confidently matters. You’re not just protecting your own business and reputation, you’re protecting your clients too.

That’s the thinking behind our approach to Cyber Confidence: helping you understand your current position, identify what needs attention and make sensible decisions about what to do next.

Received a dark web report from us?

Don't ignore it, but don't assume the worst either. Take an opportunity to check your cybersecurity toolkit leaves no gaps.