An organization may first learn about a suspected breach from customer phishing reports, a law enforcement notice, or a listing that names the company on a ransomware leak site.
Detection time varies by incident and control coverage. Treat an external-source match as a lead, then compare it with internal identity, network, endpoint, and application evidence.
The ten signals below can justify an investigation. None proves by itself that your organization's data is on the dark web.
1. Unusual Login Attempts from Unknown Locations
Login attempts from places where your company does not operate may indicate password spraying, credential stuffing, a VPN, or legitimate travel. Compare the attempt with device, account, and identity-provider evidence before concluding that credentials leaked.
What to do: Review authentication logs for failed login attempts from unusual IPs, implement geofencing if appropriate, and consider mandatory password resets for affected accounts.
2. Customers Report Receiving Targeted Phishing Emails
When cybercriminals obtain your customer database, they use it to launch convincing phishing campaigns that appear to come from your organization. If multiple customers report receiving suspicious emails that reference your company name, recent transactions, or specific products, your customer data may have been stolen.
A phishing report may help identify which customer or transaction details the sender already knows.
What to do: Alert customers about the phishing campaign, investigate the source of the data leak, and consider implementing email authentication protocols like DMARC.
3. You Receive Notifications from Have I Been Pwned or Similar Services
Services like Have I Been Pwned monitor public data breaches and notify users when their credentials appear in dumps. A notice about a corporate address confirms that the address appears in the named dataset; it does not show where else the data circulates.
What to do: Verify which accounts were affected, force password changes, enable multi-factor authentication, and investigate whether the breach originated from your systems or a third party.
4. Unexplained Financial Transactions or Fraud
Discovery of unauthorized transactions, fraudulent credit card charges on company cards, or customers reporting fraudulent activity can indicate that payment data has been stolen and is being sold or used by criminals.
Some dark web marketplaces sell "fullz," or identity profiles that can include credit card numbers, CVV codes, billing addresses, and personal information. Payment processors should compare reported fraud with their own transaction and access records.
What to do: Send the evidence to the fraud or incident owner. That owner should confirm scope and consult legal counsel before customer, regulator, or law-enforcement notification.
5. Sudden Increase in Account Takeovers
A spike in customers reporting that they can't access their accounts, or complaints about actions they didn't take, suggests credential stuffing attacks using stolen credentials. Attackers purchase credential lists from the dark web and use automated tools to test them across thousands of services.
What to do: Implement rate limiting on login attempts, require password resets for affected accounts, enable CAPTCHA on login forms, and strongly encourage multi-factor authentication.
6. Your Organization Appears in Breach Notification Databases
Websites and services track reported data breaches. If your company name appears on one of these lists, inspect the source and verify that it refers to your organization. A name match may be a claim, a historical report, or a different organization with a similar name.
Some breaches are only discovered when the stolen data is advertised for sale months or years after the initial compromise.
What to do: Verify the legitimacy of the breach report, conduct forensic investigation if confirmed, notify affected parties as required by law, and implement additional monitoring.
7. Ransomware Group Contacts or Lists Your Organization
Ransomware operators use "double extortion," combining encryption with threatened publication of stolen data. A leak-site listing is a serious lead, but the named organization and source material still require verification.
A leak-site listing may include a publication deadline intended to pressure the named organization. Preserve the page and verify the identity before treating the claim as an incident.
What to do: Preserve the evidence and route it to the incident lead. The lead should apply the activation criteria and involve legal counsel before notification, law-enforcement contact, or any payment decision.
8. Security Researchers or Vendors Notify You
Researchers and threat-intelligence vendors may collect records from selected external sources. Treat an unsolicited report as a lead that still needs evidence and source verification.
Ask for the source, timestamp, matching identifiers, and enough evidence to distinguish the organization from a namesake.
What to do: Request specific details and evidence, verify the researcher's credibility, investigate internally, and consider engaging the researcher or their organization for additional intelligence.
9. Employees Report Compromised Personal Accounts
Password reuse can connect a personal account compromise to a work account. If several employees report personal account compromises, check corporate authentication logs and require resets where the evidence supports it.
Attackers specifically target employees through credential stuffing, knowing that password reuse is common.
What to do: Educate employees about password reuse dangers, mandate unique passwords for corporate accounts, implement password managers, and require MFA for all access.
10. Network Performance Issues or Unusual Outbound Traffic
Data exfiltration can produce large transfers to unknown external IPs, connections to suspicious domains, or off-hours traffic spikes. The same patterns can also have legitimate causes, so compare them with asset and user activity.
Timely log review matters because exfiltration may finish before a scheduled retrospective review begins.
What to do: Have the network or incident owner triage the anomaly, preserve relevant logs, and apply approved containment steps when the evidence supports them.
What to Do If You Suspect a Breach
If you've identified one or more of these warning signs, take immediate action:
- Activate Incident Response: Engage your incident response team or a third-party IR firm if you don't have internal capability
- Preserve Evidence: Capture logs, screenshots, and forensic images before systems are altered
- Contain the Breach: Isolate affected systems, force password resets, revoke compromised credentials
- Investigate Scope: Determine what data was accessed, how the breach occurred, and how long attackers had access
- Notify Stakeholders: Follow the incident escalation matrix and involve legal or compliance owners where required
- Meet Legal Obligations: Many jurisdictions require breach notification within specific timeframes
- Implement Monitoring: Set up dark web monitoring to detect if additional data appears or if the incident escalates
Response record:
Record when the signal arrived, who reviewed it, what evidence supported the decision, and which response step followed.
Prevention Is Better Than Detection
While these warning signs help detect existing breaches, the best strategy is prevention:
- Implement Dark Web Monitoring: Continuously check configured organization and domain terms, measure collection and delivery latency, and review source evidence
- Enforce Strong Authentication: Apply MFA under the identity policy, prioritizing privileged and remote access
- Regular Security Assessments: Set penetration-test and vulnerability-scan cadence from risk and compliance requirements
- Employee Training: Test whether staff can identify and report the phishing scenarios relevant to their roles
- Third-Party Risk Management: Vet vendors' security practices and monitor them for compromises
- Incident Response Planning: Have a tested plan ready before you need it
Conclusion
Any one signal may have an innocent explanation. Several related signals, or a source record supported by internal evidence, should move into the incident-response process.
Review authentication, fraud, network, and external-source signals together. Record why the team accepted or rejected each match.
Measure how long a credible signal takes to reach an owner and how quickly that owner can verify it.
