A dark web alert is a warning sign
Discovering that your company’s details are available on the dark web can be worrying.
Perhaps a dark web scan has uncovered an employee’s email address and password. Maybe credentials associated with your company domain have appeared in data stolen from another organisation. Or perhaps information connected with one of your senior people is being circulated online.
The first thing to understand is that a dark web alert does not necessarily mean your company has been hacked.
But it does mean you should take it seriously.
For professional services businesses in particular, compromised credentials can give criminals a useful starting point for phishing, account takeover, impersonation and other attacks.
So what should you do next?
1. Understand exactly what has been exposed
Start by establishing what information has actually been discovered. There is a big difference between an old email address appearing in a historic data breach and a current company account appearing alongside a password that is still in use.
You need to understand:
- Which email addresses or accounts are involved
- What information has been exposed
- When the information was compromised
- Whether passwords or other credentials are included
- Whether those credentials are still being used
- Whether the same password has been reused elsewhere
This is why a dark web report should be treated as the beginning of an investigation rather than the end of one.
The important question isn’t simply “Are we on the dark web?”
It’s “What risk does this create for our business?“
2. Change compromised passwords immediately
If a password has been exposed and there is any possibility that it is still in use, change it. You should also check whether that password, or a variation of it, has been used for other accounts.
Password reuse is particularly dangerous because criminals can take credentials stolen from one service and automatically test them against Microsoft 365, email, cloud applications and other systems. One compromised password can therefore potentially become the key to several different doors.
Use strong, unique passwords and a secure password manager rather than relying on passwords people can easily remember and reuse.