dark web cybersecurity monitoring

Dark web and cybersecurity: how to turn it into an early-warning lever

October 6, 2026 Off by Password Revelator

Chronicle of Geert Baudewijns, founder and CEO of Secutec — October 6, 2026

Computer attacks continue to occur and affect both businesses and institutions. Faced with this threat, a question arises: can we spot an offensive before it is launched? In some cases, yes. The dark web, often perceived as an exclusively criminal space, can provide useful signals for cybersecurity.

FBI: a leak that shows the extent of the risk

Last week, the ShinyHunters group claimed to have compromised the FBI through FBIJobs.gov, the agency's recruiting portal. The hackers say they have exfiltrated millions of very sensitive data: identities, addresses, telephones of agents and their spouses, but also assignments, including within the secret FBI hacker unit.

If this leak is confirmed, Justin Sherman, professor at Georgetown University and specialist in American national security, believes that it could represent a disaster for counterespionage. Thousands of agents would be exposed to profiling, phishing and approach attempts by foreign services. Another concern: stolen data frequently ends up being sold or exchanged on the dark web. Monitoring them therefore makes it possible to anticipate future attacks.

Infostealer and stolen credentials: why force a door when you already have the keys?

Rather than trying to bypass traditional protections — firewalls, antivirus, multi-factor authentication, complex passwords — cybercriminals increasingly favor valid identifiers. This method is faster and leaves fewer traces than a traditional intrusion.

One click is enough to steal credentials

These identifiers often come from infostealers, malware specialized in the discreet theft of passwords, autofill data or browsing cookies. All it takes is one click on a booby-trapped link to install them. It does not matter whether the infected computer belongs to the targeted company: a service provider or supplier can offer the same entry point.

An underground market with surprisingly low prices

According to the Fortinet 2026 report, 1.7 billion stolen identifiers circulated on clandestine forums in 2024. The following year, the number of logs from infostealers detected on these spaces increased by another 79%, reaching 4.62 billion logs exchanged. The dark web is not a completely inaccessible area: in France, access is authorized via specialized browsers such as Tor. There are both legal and illegal activities. Offenses are reported to Cybermalveillance.gouv.fr.

It is on this market that stolen data is traded, often at affordable prices. A bank card number can start from €5, bank account credentials between €35 and €65, and a verified crypto account for a few hundred euros. Launching a DDoS attack is sometimes available for as little as €20.

Dark web monitoring: anticipating a cyberattack

Before a cyberattack, weak signals appear. The identifiers of the targeted company – or its suppliers – reappear, and access to its network is put up for sale. For professionals capable of interpreting them, these clues announce an imminent attack.

Spotted by threat intelligence tools that explore the dark web, then analyzed by experts, these signals alert the company. It must then react quickly: change passwords, close open sessions and notify the suppliers affected by the identified flaws. Strict password management then limits the reuse of access that has already been exposed.

Conclusion

As even the most well-protected organizations get hacked and the latest language models pose new threats to data, dark web monitoring can be more effective and cost-effective than many imagine.

FAQ

Is the dark web illegal?

No. In France, accessing it via Tor is authorized. On the other hand, the criminal activities that take place there remain illegal.

What is an infostealer?

It is malware designed to steal credentials, browsing cookies or automatically saved data.

How can a company monitor the dark web?

It can rely on threat intelligence tools, specialized analysts and automated alerts.

Why are stolen credentials dangerous?

They allow attackers to gain entry with legitimate access, impersonate a user, and in some cases bypass protections like MFA.

About the author. Geert Baudewijns is the founder and CEO of Secutec, a cybersecurity company that supports businesses, the financial sector and institutions. Cybercrime specialist and author of Negotiating in the Dark, he works on monitoring the dark web and compromised credentials to anticipate attacks.