Is my data on the dark web?
How to find out whether your hacked data is circulating on the dark web, what hackers really do with it, and why you should never try to buy it back.
After a hack, stolen databases are sold, traded and often published for free on forums, messaging channels and dark web sites. You cannot search them yourself, and you should not try: there is a safe way to find out whether you are affected.
How to find out whether my data is circulating
When a hacked database becomes public, security researchers collect it and add it to reference databases. The best known, Have I Been Pwned, lists more than 17 billion accounts from over a thousand breaches. Checking your email address on SimplComIA tells you whether it appears in one of them, without ever seeing or downloading the data itself.
That is also what "dark web monitoring" services do: compare your address with known breach databases. No service can guarantee to see a database sold privately and never published.
What hackers do with your data
- Try your passwords on other sites ("credential stuffing"): hence the importance of never reusing a password.
- Make scams convincing: fake bank adviser, fake courier, fake tech support who know your name and purchases.
- Steal your identity when ID documents, a date of birth or bank details have leaked.
- Resell the lists to other scammers, who combine them with other breaches.
Never try to buy back or browse your data
Sites offering to "find" or "buy back" your hacked data are useless at best and traps at worst: malware, fresh collection of your information, blackmail. A stolen copy does not disappear because someone bought it once.
Your data is on the dark web: what to do
- Change the affected passwords and turn on two-factor authentication.
- Depending on the exposed data, follow the steps in order.
- Ask the original site to erase what it still holds about you: see removing hacked data.
- Stay alert in the following months: data is often exploited long after the breach.