In this article:
In this article:
If your PII surfaces on a cybercrime forum or website, there are ways for you to receive early notifications. This is where Dark Web alerts come in.
In this article:
In this article:
The Dark Web is the deepest part of the internet, an anonymous network of sites and forums known for its notoriety in cybercrime and other illegal activities. When bad actors hack a company's databases, that information almost always ends up for sale on the Dark Web.
And your information is no different.
In 2022, billions of pieces of personally identifiable information (PII) were leaked to the Dark Web.
Companies and organizations ranging from Uber and Twitter to the Beijing police department were hit with massive data breaches in 2022 [*].
The problem is, even when cyberattacks are reported, details are usually murky. Companies aren't rushing to alert you that your data — that they were responsible for safeguarding — was hacked and released, putting you at risk of identity theft, account takeover, or financial fraud.
Instead, Dark Web monitoring services are one of the only ways to know if your personal data has been put at risk.
If you've received a notification that your information was found on the Dark Web, you probably want to know what to do next. In this guide, we'll explain what a Dark Web alert is and what you should do if you get one.
{{show-toc}}
A Dark Web alert is a type of security notification. It informs you that your sensitive information — such as credit card numbers, phone numbers, login credentials, email accounts, home addresses, or other PII — has surfaced somewhere on the Dark Web.
Sometimes, malicious hackers collect this information through social engineering tactics, including phishing emails or remote access scams. However, in most cases, exposure on the Dark Web is due to large-scale data breaches that affect thousands or even millions of people at once.
The Dark Web is a network of heavily encrypted web pages that basic web browsers or search engines cannot crawl. This subset of the deep web, only accessible with an anonymizing browser called Tor, tends to host a sizable number of illicit marketplaces.
The substantial minority of scammers aside, the Dark Web is an efficient space for anonymous communications, whistleblower websites, and threat analysis.
Dark Web alerts are sent after scanning the deep web for your information. A digital security and Dark Web monitoring service like Aura will first need personal details like your name, address, phone number, email, and Social Security number (SSN) to begin continuous Dark Web monitoring.
Aura then conducts Dark Web scans for the information you’ve shared. Imagine your bank was hacked and your account password was leaked. Aura will send you an alert so that you can update your online banking password and lock down your account.
There’s a good chance your information is already on the Dark Web. You can run a free security scan with your email address to see what Aura has already found.
The Dark Web isn’t the only place that should be monitored to keep your information secure. Aura also conducts 24/7 scans of these other areas.
If you receive a Dark Web alert, there are a few steps that you should take right away to secure your online accounts and identity.
For a fraud alert, contact one of the three major credit bureaus (Equifax, Experian, or TransUnion) and notify them of the breach. Fraud alerts encourage lenders and creditors to take extra steps to verify your identity (such as contacting you by phone) before opening a new credit account in your name or making changes to existing accounts.
For a credit freeze, contact each of the three bureaus separately and request to freeze your credit so that no new accounts can be opened in your name.
Get a free credit report at AnnualCreditReport.com and review recent activity on your credit reports, and verify any new accounts or transactions.
If you see evidence of suspicious activity — such as unauthorized hard inquiries — contact the lender immediately and report identity theft.
📚 Related: How To Find Out If Your Information Is on the Dark Web →
Contact the Social Security Administration (SSA) to report the possible theft of your Social Security number. You can create an account at SSA.gov and review claimed earnings to determine whether your SSN is being used by someone else.
Consider locking your SSN if you’re not actively looking for employment (or are retired).
Change the passwords for any of your accounts that have been exposed on the Dark Web. If you use the same password on other accounts, replace those as well.
Aura’s password manager can help by securely storing all of your login credentials and helping you create new, strong passwords with just a few clicks.
If your driver’s license information was stolen, the DMV may need to place a fraud alert. From there, you can start the process of getting a new license.
See if you’re eligible to place a “Verify ID” flag on your driver record. This informs law enforcement that your identity has been compromised or stolen.
📚 Related: What To Do If Your Email is Found on the Dark Web →
If your passport information has been compromised, contact Travel.state.gov to report passport fraud. Complete the DS-64 form to report a lost or stolen passport, and the DS-11 form to apply for a new United States passport.
Go into the security settings of your personal online and social media accounts and see if they offer two-factor authentication (2FA). Ideally, opt for authentication through a phone app. An authenticator app like Authy is more secure than one-time codes sent via SMS.
📚 Related: What Is Two-Factor Authentication (2FA)? How Does It Work? →
File a report with the Federal Trade Commission (FTC) on IdentityTheft.gov and obtain a copy of your Identity Theft Affidavit. Also contact your local police department with this affidavit, a government-issued photo ID, proof of your address, and any other evidence of identity theft.
Call the fraud department at other impacted organizations, like banks or credit card companies. Request written confirmation to verify that any fraudulent accounts were closed and transactions have been reversed.
📚 Related: What To Do If Your Identity Is Stolen →
Unfortunately, there are no reliable ways to scrub your information from the Dark Web. Sites that illicitly buy and sell personal data usually escape the same regulations to which legitimate websites are subject.
This is due, in part, to the layers of encryption and anonymity that characterize the Dark Web. But the dilemma is further complicated by the fact that it’s not only used by criminals.
Others that depend on the protections of the Dark Web include organizations like law enforcement, undercover intelligence, and even dissidents, whistleblowers, and victims of oppressive regimes.
This certainly doesn’t mean that the Dark Web is never regulated. But the cybercriminals that are caught and shut down by authorities usually belong to much larger operations. (This includes multimillion-dollar drug busts, child trafficking and exploitation cases, and large-scale cybersecurity breaches.)
For this reason, your information won’t be erased from the Dark Web anytime soon. Instead, the best workaround is to go on the defensive. Scanning the Dark Web yourself, however, is both dangerous and time-consuming. That’s where Aura comes in.
📚 Related: How To Remove Your Personal Information From the Internet →
There were 817 publicly-reported data compromises just in the first half of 2022 alone [*]. Even if you weren’t directly affected by any of these highly publicized data breaches, your PII could still be at risk.
And once that data is on the Dark Web, it’s available to identity thieves indefinitely. But with Aura, you get complete coverage (and peace of mind).
Editorial note: Our articles provide educational information for you to increase awareness about digital safety. Aura’s services may not provide the exact features we write about, nor may cover or protect against every type of crime, fraud, or threat discussed in our articles. Please review our Terms during enrollment or setup for more information. Remember that no one can prevent all identity theft or cybercrime.