Your company can be leaked without anyone having attacked you. All it takes is one employee signing up to a third-party service with their work email, that service suffering a breach, and the password being close enough to the one they use for company mail. From there, the combination circulates in lists that get bought, sold and traded on closed forums and private channels. Threat intelligence exists so that you find out before the person who plans to use it does.
What the dark web actually is, and what moves through it
The usual mental image of the dark web is a hidden, sophisticated marketplace. The operational reality is duller and more dangerous: much of the sensitive material circulates on restricted forums, private messaging channels and data repositories assembled from old breaches. No targeted attack against you is required for your company to show up there.
What typically surfaces about an SME fits into a few categories:
- Corporate credentials: email and password pairs from breaches at external services where someone registered with the company domain.
- Infostealer logs: dumps from an infected computer containing everything the browser had saved, including live sessions and access to admin panels.
- Customer or invoicing data leaked through one of your suppliers rather than from your own systems.
- Infrastructure detail: subdomains, exposed services, team email addresses and the technologies you run, collected with OSINT techniques that never touch your network.
- Internal documents that escaped in an attachment, a misconfigured public repository or an open storage bucket.
Why an old password is still dangerous
The mechanism that turns an old leak into a current incident is called credential stuffing. Someone takes a published list of emails and passwords and tries it automatically against dozens of services: corporate mail, VPN, the website admin panel, management tools, cloud storage. Nothing is guessed. What already worked somewhere else simply gets reused.
It works because people repeat passwords and because the variations are predictable: adding a number at the end, changing the year, swapping a letter for a symbol. A password leaked three years ago remains an excellent starting point for guessing today's.
The second route is more direct. With valid mail credentials, an attacker needs no malware at all: they log in, read the correspondence with your suppliers for weeks, and wait for the right moment to request a change of bank details inside a thread that already existed. That is the standard path into CEO fraud, and no perimeter tool sees it as an attack, because technically it is a legitimate login.
The breach that hits you is usually somebody else's
For a company of 10 to 50 employees, the most frequent exposure does not start on its own servers. It starts in the surrounding ecosystem: the marketing tool the sales team adopted, the HR platform, the project manager trialled for a couple of months, the accountancy firm handling payroll, the provider hosting your website.
That dependency runs in both directions. If your company serves larger clients, you are somebody else's third party, which is why security questionnaires arrive asking how you detect a credential leak and what you do when one happens. Having a concrete answer to that question has become part of the sales process.
What monitoring catches, and what it does not
A threat intelligence service continuously monitors your domain, your brands, corporate email addresses and visible infrastructure, and raises a flag when something turns up where it should not be. In practice it lets you:
- Learn that credentials carrying your domain have appeared in a dump, and which service they came from.
- Spot registered domains imitating yours, the usual precursor to a phishing campaign against your customers.
- See which of your services are visible from outside and what technical detail they reveal without anyone attacking them.
- Get an alert when data attributed to your company appears after a supplier's breach.
It is worth being equally clear about what it does not do. Monitoring deletes nothing: once published, information cannot be pulled back out of circulation. It does not cover every closed space, because many are private and admission is restricted. It cannot flag in time what is never published at all. And it does not prevent a leaked credential from being used; it only gives you room to invalidate it before someone tries it.
That room is the entire value. The gap between finding out from an alert and finding out from a strange bank transfer is measured in weeks.
What to do the day an alert fires
- Change the affected credential and every close relative of it on other services, starting with email and VPN.
- Kill the open sessions on that account. Changing the password does not always evict whoever is already inside.
- Turn on the second factor if it was not already there, above all on mail, remote access and administration.
- Review the sign-in logs for the past weeks: odd locations, impossible hours, automatic forwarding rules created in the mailbox.
- Assess whether personal data is involved, because then GDPR applies and the Article 33 notification clock starts from the moment you become aware.
The first four steps take an afternoon when you already know who executes them. Improvised on the day, they take a week.
Make it routine rather than a scare
External monitoring earns its place when it runs continuously, because exposure appears whenever it feels like it: a breach at a supplier, an infected home computer, a new service signed up with a team address. A threat intelligence service keeps that watch running and turns each finding into a specific action instead of one more alert.
It works best paired with two things: vulnerability management that fixes whatever the watch flags as exposed, and a cyberattack simulation that tests how far someone would get using exactly those leaked credentials. Knowing what is out there about your company is the first step. Reducing it is the one that counts.
Want to know how exposed your website is?
Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.