← Knowledge Base

Dark Web Monitoring: What It Is, and Why Have I Been Pwned Does It Free

  • Security
  • Privacy
  • Breaches
  • Passwords

TL;DR

“Dark web monitoring” sounds like a service quietly prowling the shadowy corners of the internet for your secrets. Mostly, it is just checking whether your email address has turned up in a known data breach, and you can do that yourself, for free. Have I Been Pwned (haveibeenpwned.com) lets you check any email and will email you if you show up in a future breach.


Now for the more technical explanation

What is dark web monitoring?

The name is marketing. There is no clever robot infiltrating dark web forums on your behalf. In practice, “dark web monitoring” means matching your identifiers (usually your email address) against aggregated breach data: the leaked databases, credential dumps, and paste sites that get traded after a company is hacked. When your address is found in one of those dumps, the service tells you.

That is genuinely useful information, “your details were in the LinkedIn / Dropbox / whatever breach, so change that password”, but it is not magic, and it is not rare or expensive to provide.

Have I Been Pwned does the essential part free

Have I Been Pwned (HIBP), run by the well-respected security researcher Troy Hunt, is the go-to, and it is free for individuals:

HIBP is so trusted that browsers, password managers, and even government agencies build on its data.

Your password manager probably already does it

If you use a password manager (and you should, see the password manager guide), it likely includes breach checking already: 1Password’s Watchtower, Bitwarden’s reports, and similar features use HIBP-style data to flag breached, reused, and weak passwords across your whole vault. So you may already have “dark web monitoring” and better, without paying a cent extra.

So what are you actually paying for with the premium version?

Paid identity-protection services do monitor more than your email: things like your national ID or tax number, credit cards, bank accounts, phone number, and passport, and some do actively watch dark web markets and forums for those. They also usually bundle identity-theft insurance and remediation help (someone to guide you through recovering if your identity is stolen).

For a genuinely high-risk person (a prior identity-theft victim, someone being specifically targeted), that can be worth it. For most people, the free breach check plus good password hygiene covers the 90% that matters.

It is worth noticing where you usually meet this feature, though. Dark web monitoring has quietly become one of the standard hooks antivirus companies use to move people up to a paid suite, sitting in the tier-comparison table next to the bundled VPN and the “PC optimiser” as another tick in the premium column. It is a commodity feature with a frightening name, which makes it excellent marketing. That does not make it worthless, but it does mean people often end up paying for a whole antivirus subscription to get something Have I Been Pwned would have given them free (see the antivirus vs EDR guide).

The lag: an alert is not an early warning

Here is something the marketing implies without ever quite claiming: that monitoring gives you a timely heads-up. In practice the delay between “your data was stolen” and “you get an email about it” is often months, sometimes years, and sometimes forever. It varies enormously case by case, but the reasons are consistent.

Stolen data has a commercial life before it has a public one. A threat actor who has just emptied a company’s user table has something valuable, and the way to realise that value is to sell it, quietly, to the highest bidder. Fresh records command a premium for roughly the first 30 to 90 days, after which prices fall steeply, often by 70 to 80%. The free, widely-circulated dump that monitoring services can actually see tends to be the end of that pipeline, not the start. By the time a set of credentials is cheap enough to be everywhere, it has frequently changed hands privately more than once.

The company often has not told anyone yet either. Troy Hunt, who runs Have I Been Pwned and has loaded over a thousand breaches into it, wrote a piece titled “1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever”, arguing the delay is getting longer rather than shorter, partly because organisations now weigh class-action exposure before they weigh telling you. Some famous breaches (LinkedIn, Dropbox) took years to surface publicly. Others (Disqus, imgur) were not known to anyone, including the companies, until years afterwards.

Speed varies wildly at the other end, too. Credentials harvested by infostealer malware can be packaged and on sale within 24 to 48 hours, which is far faster than any monitoring service will reach you. So this is not a rule with a fixed number attached; it is a reason not to trust silence.

The practical consequences are worth stating plainly:

None of this makes monitoring pointless. It makes it a historical record rather than a tripwire, which is a perfectly useful thing to have as long as you know which one you bought.

The honest bit: monitoring is reactive

Here is the part the marketing skips. All monitoring is reactive: it tells you after your data is already out there. It is a smoke alarm, not a lock on the door. The thing that actually protects you is prevention:

Get those two right and a breach alert becomes a minor chore (“change that one password”) rather than a crisis.

A note for businesses

Monitoring at scale is a legitimate paid use. HIBP offers a paid API to monitor an entire domain, so you can be alerted when any of your users appears in a breach. That is exactly what breach-check tools like the ones in the Scripts section use. Paying for domain-wide monitoring is sensible; paying a consumer suite to monitor one personal email is not.

What to do right now

  1. Check your email at haveibeenpwned.com and turn on notifications.
  2. Use a password manager with unique passwords and built-in breach checks.
  3. Turn on MFA, phishing-resistant where you can.
  4. Consider paid identity monitoring only if you have a specific high-risk need, and check whether you are buying the feature itself or an entire antivirus subscription wrapped around it.
  5. Do not read silence as safety. Keep the password hygiene up regardless of what the dashboard says, because the alert may be months behind the theft.

The short version

“Dark web monitoring” is mostly breach-checking, and Have I Been Pwned does that free, alerts included, while your password manager likely does too. Paid services monitor more of your identity and add insurance, worth it for a few, overkill for most, and a favourite way for antivirus companies to justify a premium tier. Remember it is both reactive and slow: stolen data is usually sold privately long before it is dumped where anyone can scan for it, so a quiet inbox proves nothing. Unique passwords plus MFA are what actually keep you safe.

Written by Tom Langston, IT Infrastructure and Cybersecurity.