1. Help centre
  2. Your services
  3. Dark Web Scan
  • Welcome to HackRisk
  • Getting started
  • Reading your dashboard
  • Sophia, your AI assistant
  • Dark Web Scan
  • Vulnerability Scan
  • Recon Scan
  • Supply Chain Risk
  • Security Awareness & Phishing
  • Managing your account

Dark Web Scan

Where your people's credentials have been exposed in breaches and on the dark web.

Loading documentation…

Sophia, your AI assistant< PreviousVulnerability ScanNext >

Powered by heyo

On this page

OverviewDark Web BreachesIndividualsManaging breaches

Dark Web Scan shows you where information linked to your company's domains has been exposed in data breaches and on the dark web.

Overview

The dark web is the part of the internet that standard browsers cannot reach. Criminals often use it because it offers greater anonymity.

Dark Web Scan monitors it for data connected to the domains on your account. New matches are picked up continuously, usually within around six hours, rather than on a fixed nightly schedule.

On the Dark Web Scan page you will see:

  • An overall score for the module, based on the number of breaches found.
  • Your top five risks.
  • A graph showing how often breaches have occurred over the past 12 months.

HackRisk can also tell you whether a breach includes password information, and whether the same password has been reused across more than one breach.

Dark Web Breaches

Every breach found is listed in the Dark Web Breaches table. By default, you see breaches published in the last 12 months. Use the filters to look further back, up to three years.

If you are on a free trial, you will see only the five most recent breaches.

Select the arrow on the left of a breach to expand it. The expanded view shows:

  • The date the breach was published.
  • The related breach data. Any credentials are partially hidden for your security.
  • The source of the breach and a summary of what is known about it, where available.

At the bottom of the panel, the More Information link takes you to guidance on responding to a breach and reducing its impact.

Individuals

Further down the page, breaches are grouped by email address. This makes it easy to see whether one person appears in several breaches.

Each person is given their own risk score, based on:

  • How many breaches they appear in.
  • Whether a password was exposed.
  • Whether the same password appears in more than one breach.

A reused password is the most serious of these, because one leak can unlock several accounts.

Managing breaches

Once data is on the dark web, there is usually little that can be done to remove it at the source. What you can do is reduce the risk it creates, and record that you have done so.

Each breach has an Acknowledge button. Depending on your screen size, it appears in one of two places.

  1. Select Acknowledge on the breach.
  2. Read the panel, which explains how breaches happen and suggests practical steps to reduce the risk.
  3. Tick the actions you have completed. You can also add a comment. Both are optional, and both are stored for reporting.
  4. Confirm the acknowledgement.

The breach is then marked as Acknowledged and moved to the bottom of the list. It no longer counts towards the Dark Web Scan graph or score, so acknowledging breaches as you deal with them helps your score improve over time.

Typical steps include asking affected people to change their password, making sure each account has a unique password, and turning on multi-factor authentication.