Skip to content
← Malware and the hidden internet

Lesson 6 of 7 · 7 min

The dark web: what it really is, and why your data ends up there

Surface web, deep web, dark web: three very different things. Learn what the dark web actually contains, how stolen data reaches it, and what you can do when yours does.

The dark web is often described as a vast criminal underworld hiding beneath the internet. The reality is both smaller and more ordinary. It is a small part of the internet that you can only reach with special software, most often Tor, and that was designed to hide who runs a site and who visits it. That anonymity protects dissidents and whistleblowers. It also attracts criminal markets, which is why your stolen data may pass through it.

Surface, deep and dark: three different things

LayerWhat it isExamples
Surface webPages that search engines index and anyone can openNews sites, public blogs, shop pages
Deep webEverything behind a login or not indexed by search engines; most of the web, and mostly harmlessYour email inbox, online banking, private cloud folders, company intranets
Dark webSites only reachable through anonymity networks such as Tor, with addresses ending in .onionSecure drop boxes for journalists, privacy-friendly mirrors of news sites, and also criminal forums and markets

The deep web and the dark web are often confused. Your email inbox is part of the deep web simply because it is private; there is nothing dark about it. The dark web is defined by the technology used to reach it and by the anonymity it provides.

What is actually there

Some well-known organisations run official .onion versions of their sites so that people in countries with censorship or surveillance can reach them safely. Several newsrooms use onion-based secure drop systems to receive documents from sources. At the same time, criminal forums and marketplaces use the same anonymity to trade in drugs, stolen data, hacking tools and services. Law enforcement agencies, including Europol, regularly take such markets down, and new ones appear. Many of the “terrifying” things people describe are scams: dark-web shoppers are themselves frequent victims of fraud.

How your data ends up there

  • Data breaches: a company you use is hacked, and its customer database (emails, passwords, addresses, sometimes more) is sold or leaked.
  • Infostealers: malicious software on someone’s computer collects saved passwords and session cookies; the stolen “logs” are sold in bulk.
  • Ransomware leaks: groups practising double extortion publish stolen company data on their own leak sites when victims refuse to pay.
  • Phishing kits: fake login pages collect credentials that are then resold.

What happens next is mostly automated. Criminals combine leaked email addresses and passwords into huge lists and try them on other services, a technique called credential stuffing. It works because so many people reuse the same password. Personal details are also used to make phishing messages more convincing: a fraudster who knows your address and the shop you ordered from can write a very believable message.

Checking whether you are affected

You do not need to visit the dark web to find out whether your data has leaked, and you should not. Services such as Have I Been Pwned, run by security researcher Troy Hunt, let you check whether your email address appears in known breaches, and many password managers now warn you when a saved password shows up in a leak. Some “dark web monitoring” services are useful; others mostly sell reassurance. The free check and a good password manager cover most of what an individual needs.

What to do when your data has leaked

  • Change the password of the affected account, and of every other account that used the same password.
  • Use a password manager so that every account gets its own long, random password from now on.
  • Turn on two-factor authentication, preferably passkeys or an authenticator app.
  • Be extra suspicious of messages that mention details from the breach; criminals use them to seem legitimate.
  • If financial or identity data leaked, watch your bank statements and consider the fraud protections your country offers.

Anonymous is not the same as untouchable

The dark web’s anonymity is strong, but it is not magic. Police and international agencies such as Europol have shut down many criminal marketplaces over the years. Often the technology held up and the people did not: operators and buyers were identified through mistakes made elsewhere, such as a reused username, a personal email address, a shipping address, or money traced as it moved between cryptocurrency and ordinary bank accounts. For ordinary users, the lesson runs the other way too: curiosity visits to criminal marketplaces are pointless and risky. Scams are everywhere there, and downloading anything from such sites is a reliable way to infect your own computer.

The link with your own computer

Most leaks happen on other people’s servers, and nothing on your Mac can stop a company from being breached. What you can control is whether your own computer becomes a source: an infostealer on your Mac hands your passwords straight to the market. Keeping software updated, avoiding cracked apps and watching what connects to the internet all reduce that risk. FireAI shows which apps send data where and can block an unknown app before its first connection; its optional threat lists can also flag connections to known malicious servers. It cannot see or remove data that has already leaked elsewhere.

Key takeaways

  • The deep web is simply everything not indexed by search engines, like your inbox; the dark web is the small part reachable only through anonymity networks such as Tor.
  • The dark web hosts both legitimate privacy services and criminal markets that trade stolen data.
  • Data reaches those markets through breaches, infostealers, ransomware leaks and phishing.
  • Check breaches with a free service such as Have I Been Pwned, and never reuse passwords.

Check yourself

  1. 1. Your online banking pages are part of which layer of the web?

    • The dark web
    • The deep web: private, behind a login and not indexed by search engines — Right.
    • The surface web
    • None: banks are not on the web

    The deep web is everything not indexed by search engines, including logged-in services. It is ordinary and mostly harmless.

  2. 2. Why does a leaked password from one website put your other accounts at risk?

    • Websites share passwords with each other
    • Criminals automatically try leaked email and password pairs on other services (credential stuffing), which works when passwords are reused — Right.
    • Passwords expire when leaked
    • It does not put other accounts at risk

    Credential stuffing exploits password reuse. A unique password per account stops a single leak from spreading.

  3. 3. Someone offers to remove your data from the dark web for a fee. What is the most likely situation?

    • A normal service that works well
    • A scam: data copied by criminals cannot be recalled — Right.
    • A government programme
    • A requirement under data protection law

    Once stolen data has been copied and sold, no one can guarantee its removal. These offers are a common fraud.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs