Buying data on the dark web doesn't protect companies — it funds cybercriminals
Stolen corporate credentials and databases routinely end up on the dark web, where they are traded and reused in future attacks. Security experts warn that companies engaging with this environment — buying information, paying for services or negotiating with attackers — rarely reduce their immediate risk and systematically strengthen the criminal market. The dark web is now a core part of modern cybercriminal infrastructure.
Full text
Data leaks and corporate breaches have become routine. In many cases, stolen credentials, databases , or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.
This raises a question for businesses : if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers?
The short answer is no.
Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal infrastructure . The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.
The nature of the dark web
The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.
It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.
Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, malware , exploit kits, and attack services.
The economics of cybercrime
A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.
Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.
This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.
A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.
Dark web intelligence and false signals
As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.
In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.
Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated.
The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.
As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.
Never pay cybercriminals
Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.
The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.
Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.
A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal documents . HBO reportedly transferred $250,000, but the material leaked anyway.
The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.
Common mistakes when dealing with the dark web
When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.
Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.
Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual security controls.
Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.
Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.
Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims.
What businesses should do instead
Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.
More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.
Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability management , monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.
We've featured the best secure file sharing.
This article was produced as part of TechRadar Pro Perspectives , our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Should companies be allowed to buy back their own stolen data from the dark web?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!