AEO Answer

What Is the Dark Web and Should UK Businesses Be Worried?

The dark web is a hidden layer of the internet reachable only through anonymising software like Tor and never indexed by Google. It hosts privacy tools, but also criminal marketplaces where stolen business credentials, financial data and network access are bought and sold.

Quick answer

The dark web is a hidden layer of the internet reachable only through anonymising software like Tor and never indexed by Google. It hosts privacy tools, but also criminal marketplaces where stolen business credentials, financial data and network access are bought and sold. UK businesses should treat it as a live risk, not background noise.

Key Points

What the dark web is and why UK businesses should treat it as a credential-exposure risk.

Not indexed, reached only via Tor

The dark web is the part of the internet accessible only through specialised software like Tor and not indexed by standard search engines. It hosts legitimate privacy tools alongside criminal marketplaces.

Your stolen data is the product

Employee email credentials, customer databases, financial records, and VPN or remote desktop access are all traded there. Ransomware groups also sell initial access to compromised organisations.

Phishing is the usual entry point

Credentials reach the dark web via phishing, third-party breaches where passwords were reused, and password-harvesting malware. 85% of breached businesses identified phishing as the vector (DSIT 2025).

Controls beat waiting for takedowns

Law enforcement disrupts marketplaces but new ones replace them quickly. MFA, credential monitoring and staff awareness are the practical defence — yet only 40% of UK businesses have two-factor authentication enabled (DSIT 2025).

Quick Comparison

Feature
Option A
Option B

The uncomfortable part: your staff's stolen passwords can sit on a dark web market for months before anyone uses them to break into your systems. That gap between theft and exploitation is exactly where a security-first provider earns its keep. If you want the operational view of how that data gets caught early, read our managed cybersecurity approach, which treats credential exposure as a monitored, alertable event rather than an after-the-fact surprise.

What exactly is the dark web?

The dark web is the portion of the internet that standard browsers and search engines cannot reach. You get to it with specialised software such as Tor, which anonymises traffic by routing it through multiple relays. It is not inherently criminal — journalists and privacy advocates use it — but its anonymity also shelters illegal marketplaces.

It helps to separate three layers:

  • Surface web — everything Google indexes: public websites, blogs, product pages.
  • Deep web — content behind logins or paywalls: your email inbox, online banking, internal portals. Most of the internet sits here, and it is not sinister.
  • Dark web — sites deliberately hidden and reachable only via Tor or similar networks.

The confusion usually comes from treating "deep web" and "dark web" as the same thing. They are not. Your CRM login page is deep web. A marketplace selling that login is dark web.

What is the difference between the surface web, deep web and dark web?

The surface web is indexed and openly searchable, the deep web is legitimate content gated behind authentication, and the dark web is intentionally concealed infrastructure accessed through anonymising tools. Only the third layer is where stolen business data is routinely traded, which is why it matters to UK decision-makers.

LayerHow you reach itIndexed by Google?Typical contentBusiness risk
Surface webAny browserYesPublic sites, marketing pagesLow
Deep webBrowser + loginNoEmail, banking, internal appsMedium (if credentials leak)
Dark webTor / specialist softwareNoHidden marketplaces, forumsHigh (your data may be for sale)

The practical takeaway: you cannot monitor the dark web by browsing it casually, and you should not try. What you can do is monitor whether your domains, mailboxes and credentials have surfaced there — covered in our guide to dark web monitoring.

What business data is sold on the dark web?

The product on dark web marketplaces is your data. Employee email credentials, customer databases, financial records, and VPN or remote desktop access into corporate networks are all traded openly. Ransomware groups also sell "initial access" — a working route into an organisation — to other criminals who carry out the actual attack.

What changes hands most often:

  • Email and Microsoft 365 logins — the master key to most businesses, because email resets everything else.
  • Reused passwords — harvested from unrelated breaches, then tried against your systems.
  • VPN and remote desktop access — a direct tunnel into the network.
  • Customer and financial records — sold for fraud or used as ransomware leverage.

With "22% of breaches involving compromised credentials (Verizon DBIR 2025)", stolen logins are not a fringe concern — they are one of the most common ways attackers get in. The UK government's annual Cyber Security Breaches Survey tells the same story at national scale: credential theft and phishing dominate the breach data year after year.

How do business credentials end up on the dark web?

Credentials reach the dark web through phishing, third-party breaches where staff reused passwords, and malware that quietly harvests saved browser logins. Once stolen, they are sold in bulk or used directly to access corporate systems. Email compromise is the most common starting point by a wide margin.

The usual routes, in order of how often we see them:

1. Phishing — a convincing email tricks a member of staff into typing their password into a fake login page. 2. Password reuse — a breach at an unrelated service exposes a password your employee also uses at work. 3. Infostealer malware — malicious software grabs saved passwords, cookies and session tokens from the browser. 4. Social engineering — an attacker manipulates someone into handing over access directly.

The data backs the ranking. "85% of breached businesses identified phishing as the vector (DSIT 2025)" — which is why email security and staff awareness are the highest-leverage controls most SMEs can deploy. If phishing is your front door, harden it: our email security service exists precisely to stop the messages that start this chain. The NCSC's guidance on phishing is a sound, free starting point for any UK business.

Can law enforcement shut the dark web down?

No — not in any lasting way. Agencies like the National Crime Agency regularly seize marketplaces and arrest operators, but replacements appear within weeks because the infrastructure is decentralised and anonymous. Waiting for a takedown is not a strategy. The controls you own — multi-factor authentication, monitoring and staff training — are what actually protect you.

This is the part businesses get wrong. They read about a marketplace being seized and assume the threat receded. It did not. The data already traded is still out there, and a new market is already trading it.

The gap is preventable but widely ignored. Only "40% of UK businesses have two-factor authentication enabled (DSIT 2025)", which means stolen passwords remain directly usable at most companies. Turning on multi-factor authentication is the single cheapest, highest-impact control available — the NCSC strongly recommends MFA for exactly this reason.

How should UK businesses defend against dark web threats?

Defence is about closing the loop between theft and exploitation: stop credentials leaking, detect them when they do, and make stolen ones useless. That means layered controls — MFA, credential monitoring, fast detection and staff awareness — rather than any single product. The goal is to make a stolen password worthless before it is ever used.

What we recommend, in priority order:

  • Enforce MFA everywhere, especially on Microsoft 365 and remote access. A stolen password alone should never grant entry.
  • Monitor for exposed credentials so a leak triggers an alert and a forced reset, not a breach.
  • Detect and respond fastmanaged detection and response backed by AMVIA's in-house 24/7 SOC catches the use of stolen access in minutes, not months.
  • Train your people — phishing is the number-one entry point, so the inbox is the front line.
  • Have a plan for when prevention fails — a tested incident response process turns a crisis into a procedure.

One provider, security-first, with Microsoft-certified engineers is how AMVIA keeps these controls joined up rather than scattered across vendors who each see only their slice of the problem.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.