Find out what's already circulating.
Leaked credentials, marketplace listings, forum chatter, traffic to and from your network — nine separate intelligence sources, checked against your organisation. Give us your domain and we'll tell you what's out there.
No agent to install. No access to your systems. Nothing to uninstall afterwards.
Your domain. That's the whole input.
You don't give us access to anything. We check your organisation against dark web intelligence gathered from outside your perimeter, then send you what we find.
Tell us who you are
Your domain, and where to send the results. No agent, no connector, no read access to your tenant or your network.
We run the report
Your organisation is checked against nine intelligence sources spanning marketplaces, forums, messaging platforms, paste sites and dark web traffic.
You get it by email, usually within a working day
A written snapshot of what was found across each source, and what the findings imply for your likelihood of an incident.
Nine places your organisation might already appear.
Most "dark web scans" mean leaked passwords and nothing else. Credentials are one of the nine sources in this report.
Compromised users
Usernames and passwords tied to your domain that have surfaced in breach data. Still one of the most common ways an attacker gets in.
Marketplace listings
Your data — or access to your systems and infrastructure — advertised for sale on dark web markets.
Forum posts
Your organisation discussed on criminal forums, where targeting, tooling and exploits get traded before an attack.
Messaging platform chatter
Mentions on platforms such as Telegram, routinely used to trade leaked credentials and coordinate before an attack.
Paste site results
Plain-text repositories where stolen data is dumped, often the first public place a leak appears.
Dark web pages
References to your organisation on hidden services that don't appear in any conventional search index.
Outgoing dark web traffic
Connections from your network out to the dark web — a possible indicator of malware or insider activity.
Incoming dark web traffic
Connections from the dark web to your infrastructure, often reconnaissance and scanning ahead of an attempt.
Open source intelligence
Publicly available information about your internet-facing assets, pulled together into one view of what's visible.
Three things, in writing.
No dashboard to log into and no trial to start. The snapshot arrives by email as a document you can forward to your board.
Your exposure
How many times your name, data or domain has been detected across each of the nine intelligence sources.
How findings relate to breach risk
The relationship between dark web findings and the likelihood of a cyber incident, drawn from an independent study rather than our own marketing.
Your resulting risk of breach
What the specific combination of signals found for your organisation implies about your likelihood of an incident.
The link between dark web exposure and breach risk isn't our opinion.
The correlations behind this report were independently validated by the Marsh McLennan Cyber Risk Intelligence Center, whose analysis found the underlying dataset correlates with cyber insurance loss frequency. In other words: organisations showing up across more of these sources go on to have more incidents.
Source: The Correlation Between Dark Web Exposure and Cybersecurity Risk, Marsh McLennan Cyber Risk Intelligence Center with Searchlight Cyber, whose dark web intelligence platform produces this report.
Why that matters to you
Before you request one
Can I check whether my organisation's information is on the dark web?
What do I have to give you access to?
How long does it take?
What if my snapshot finds nothing?
What should I do if it does find something?
Will this turn into a sales process?
Find out what's already out there.
Your domain, and where to send it. That's all we need.
We use your details to produce and send your snapshot. No agent, no system access, and no obligation.
Background, if you want it
What the dark web knows about you
How company data ends up on criminal marketplaces, and why the gap between a breach and its use is longer than most people assume.
Read it VideoWhat are spoof domains?
Look-alike domains registered against your brand, how they're used against your staff and customers, and how to spot them.
Watch it ArticleWhy can't I get threat intelligence relevant to my business?
Most intelligence feeds tell you about the world. The useful question is what's happening to you specifically.
Read itExposure doesn't stop changing after the report.
The snapshot tells you where you stand today. Continuous monitoring tells you the moment it changes — and that's what our managed service is for.