What Is the Dark Web and Should UK Businesses Be Worried?
The dark web is a hidden layer of the internet reachable only through anonymising software like Tor and never indexed by Google. It hosts privacy tools, but also criminal marketplaces where stolen business credentials, financial data and network access are bought and sold.
Quick answer
The dark web is a hidden layer of the internet reachable only through anonymising software like Tor and never indexed by Google. It hosts privacy tools, but also criminal marketplaces where stolen business credentials, financial data and network access are bought and sold. UK businesses should treat it as a live risk, not background noise.
Key Points
What the dark web is and why UK businesses should treat it as a credential-exposure risk.
Not indexed, reached only via Tor
The dark web is the part of the internet accessible only through specialised software like Tor and not indexed by standard search engines. It hosts legitimate privacy tools alongside criminal marketplaces.
Your stolen data is the product
Employee email credentials, customer databases, financial records, and VPN or remote desktop access are all traded there. Ransomware groups also sell initial access to compromised organisations.
Phishing is the usual entry point
Credentials reach the dark web via phishing, third-party breaches where passwords were reused, and password-harvesting malware. 85% of breached businesses identified phishing as the vector (DSIT 2025).
Controls beat waiting for takedowns
Law enforcement disrupts marketplaces but new ones replace them quickly. MFA, credential monitoring and staff awareness are the practical defence — yet only 40% of UK businesses have two-factor authentication enabled (DSIT 2025).
Quick Comparison
| Feature | Option A | Option B |
|---|
The uncomfortable part: your staff's stolen passwords can sit on a dark web market for months before anyone uses them to break into your systems. That gap between theft and exploitation is exactly where a security-first provider earns its keep. If you want the operational view of how that data gets caught early, read our managed cybersecurity approach, which treats credential exposure as a monitored, alertable event rather than an after-the-fact surprise.
What exactly is the dark web?
The dark web is the portion of the internet that standard browsers and search engines cannot reach. You get to it with specialised software such as Tor, which anonymises traffic by routing it through multiple relays. It is not inherently criminal — journalists and privacy advocates use it — but its anonymity also shelters illegal marketplaces.
It helps to separate three layers:
- Surface web — everything Google indexes: public websites, blogs, product pages.
- Deep web — content behind logins or paywalls: your email inbox, online banking, internal portals. Most of the internet sits here, and it is not sinister.
- Dark web — sites deliberately hidden and reachable only via Tor or similar networks.
The confusion usually comes from treating "deep web" and "dark web" as the same thing. They are not. Your CRM login page is deep web. A marketplace selling that login is dark web.
What is the difference between the surface web, deep web and dark web?
The surface web is indexed and openly searchable, the deep web is legitimate content gated behind authentication, and the dark web is intentionally concealed infrastructure accessed through anonymising tools. Only the third layer is where stolen business data is routinely traded, which is why it matters to UK decision-makers.
| Layer | How you reach it | Indexed by Google? | Typical content | Business risk |
|---|---|---|---|---|
| Surface web | Any browser | Yes | Public sites, marketing pages | Low |
| Deep web | Browser + login | No | Email, banking, internal apps | Medium (if credentials leak) |
| Dark web | Tor / specialist software | No | Hidden marketplaces, forums | High (your data may be for sale) |
The practical takeaway: you cannot monitor the dark web by browsing it casually, and you should not try. What you can do is monitor whether your domains, mailboxes and credentials have surfaced there — covered in our guide to dark web monitoring.
What business data is sold on the dark web?
The product on dark web marketplaces is your data. Employee email credentials, customer databases, financial records, and VPN or remote desktop access into corporate networks are all traded openly. Ransomware groups also sell "initial access" — a working route into an organisation — to other criminals who carry out the actual attack.
What changes hands most often:
- Email and Microsoft 365 logins — the master key to most businesses, because email resets everything else.
- Reused passwords — harvested from unrelated breaches, then tried against your systems.
- VPN and remote desktop access — a direct tunnel into the network.
- Customer and financial records — sold for fraud or used as ransomware leverage.
With "22% of breaches involving compromised credentials (Verizon DBIR 2025)", stolen logins are not a fringe concern — they are one of the most common ways attackers get in. The UK government's annual Cyber Security Breaches Survey tells the same story at national scale: credential theft and phishing dominate the breach data year after year.
How do business credentials end up on the dark web?
Credentials reach the dark web through phishing, third-party breaches where staff reused passwords, and malware that quietly harvests saved browser logins. Once stolen, they are sold in bulk or used directly to access corporate systems. Email compromise is the most common starting point by a wide margin.
The usual routes, in order of how often we see them:
1. Phishing — a convincing email tricks a member of staff into typing their password into a fake login page. 2. Password reuse — a breach at an unrelated service exposes a password your employee also uses at work. 3. Infostealer malware — malicious software grabs saved passwords, cookies and session tokens from the browser. 4. Social engineering — an attacker manipulates someone into handing over access directly.
The data backs the ranking. "85% of breached businesses identified phishing as the vector (DSIT 2025)" — which is why email security and staff awareness are the highest-leverage controls most SMEs can deploy. If phishing is your front door, harden it: our email security service exists precisely to stop the messages that start this chain. The NCSC's guidance on phishing is a sound, free starting point for any UK business.
Can law enforcement shut the dark web down?
No — not in any lasting way. Agencies like the National Crime Agency regularly seize marketplaces and arrest operators, but replacements appear within weeks because the infrastructure is decentralised and anonymous. Waiting for a takedown is not a strategy. The controls you own — multi-factor authentication, monitoring and staff training — are what actually protect you.
This is the part businesses get wrong. They read about a marketplace being seized and assume the threat receded. It did not. The data already traded is still out there, and a new market is already trading it.
The gap is preventable but widely ignored. Only "40% of UK businesses have two-factor authentication enabled (DSIT 2025)", which means stolen passwords remain directly usable at most companies. Turning on multi-factor authentication is the single cheapest, highest-impact control available — the NCSC strongly recommends MFA for exactly this reason.
How should UK businesses defend against dark web threats?
Defence is about closing the loop between theft and exploitation: stop credentials leaking, detect them when they do, and make stolen ones useless. That means layered controls — MFA, credential monitoring, fast detection and staff awareness — rather than any single product. The goal is to make a stolen password worthless before it is ever used.
What we recommend, in priority order:
- Enforce MFA everywhere, especially on Microsoft 365 and remote access. A stolen password alone should never grant entry.
- Monitor for exposed credentials so a leak triggers an alert and a forced reset, not a breach.
- Detect and respond fast — managed detection and response backed by AMVIA's in-house 24/7 SOC catches the use of stolen access in minutes, not months.
- Train your people — phishing is the number-one entry point, so the inbox is the front line.
- Have a plan for when prevention fails — a tested incident response process turns a crisis into a procedure.
One provider, security-first, with Microsoft-certified engineers is how AMVIA keeps these controls joined up rather than scattered across vendors who each see only their slice of the problem.
Frequently Asked Questions
The dark web is a hidden part of the internet you can only reach with anonymising software like Tor, and which search engines do not index. It is used for legitimate privacy as well as criminal marketplaces. For businesses, it matters because stolen logins, customer data and network access are bought and sold there.
Accessing the dark web is not illegal in the UK — the Tor network itself is a legal privacy tool. What is illegal is buying, selling or accessing criminal goods and services found there. For most businesses there is no reason to visit it; the right response is to monitor whether your data has appeared on it, not to browse it.
Employee email and Microsoft 365 credentials, customer databases, financial records, and VPN or remote desktop access are all traded on dark web marketplaces. Ransomware groups also sell initial access into compromised organisations. With "22% of breaches involving compromised credentials (Verizon DBIR 2025)", your data can appear there long before you notice a breach.
Credentials reach the dark web mainly through phishing, breaches at third-party services where passwords were reused, and malware that harvests saved browser logins. They are then sold in bulk or used directly. With "85% of breached businesses identified phishing as the vector (DSIT 2025)", email compromise is the most common starting point.
Agencies regularly seize marketplaces and arrest operators, but new platforms replace them quickly because the infrastructure is decentralised and anonymous. Waiting for enforcement is not a defence. Practical controls — MFA, credential monitoring and staff awareness — are what protect you. Only "40% of UK businesses have two-factor authentication enabled (DSIT 2025)", leaving stolen credentials highly exploitable.
You find out through dark web monitoring, which scans marketplaces and breach dumps for your domains, mailboxes and credentials, then alerts you so you can force password resets before the data is used. AMVIA includes this in its managed security service, pairing detection with the response needed to act on a hit.
Related Questions
What Is Multi-Factor Authentication?
MFA prevents stolen credentials found on the dark web from being used to access your accounts.
What Is Ransomware?
Ransomware tools and stolen credentials are frequently traded on dark web marketplaces.
Cybersecurity Guide for UK SMEs
How to protect your business from threats that originate on the dark web.
Protect your business → Get Cybersecurity Assessment