Skip to content
Security Updated Noah Stegman

Dark Web Monitoring for Small Business: Is It Worth It?

What dark web monitoring really does, the free tools that cover most small businesses, what to do when a password shows up, and when paying makes sense.

Dark web monitoring is a service that checks collections of stolen data for your email addresses or company domain and alerts you when it finds a match. It is a modest control. It tells you about an exposure after it has happened, and it cannot remove anything. For most small businesses, free tools cover the basics, and multi-factor authentication plus unique passwords do far more to keep accounts safe.

What Dark Web Monitoring Actually Is

The “dark web” means websites reachable only through anonymizing software such as the Tor browser. Some of those sites, along with ordinary forums and messaging channels, are used to trade stolen usernames and passwords.

Those credentials mostly come from two places:

  1. Breaches at other companies. A retailer, a software vendor, or an online service is breached, and its customer list, including email addresses and sometimes passwords, ends up in circulation. If an employee signed up with a work address, that address is in the list.
  2. Infostealer malware. Malicious software on a computer copies the passwords and sign-in cookies saved in the browser and sends them to a criminal. The resulting files are often referred to as stealer logs.

A monitoring service gathers as much of this material as it can and searches it for your identifiers. Criminals then try the exposed email and password pairs against other services, a technique known as credential stuffing. That only works where the same password was reused and no second sign-in step is required.

What It Is and Is Not

Dark web monitoring doesIt does not
Tell you that an email address and sometimes a password appeared in a known collection of stolen dataPrevent the theft, or remove the data once it is out
Give you a reason to reset a specific passwordSee everything. No service has access to every private channel where data is sold
Show which staff accounts appear in breaches most oftenTell you whether anyone has actually signed in to your systems. Your own sign-in logs do that
Support a record that you check for exposed credentialsReplace MFA, a password manager, or endpoint protection

An alert can concern a breach from many years ago and a password that has since been changed. Google retired its own consumer dark web report in early 2026, and said the reason was that the report did not give people helpful next steps. It pointed users to Password Checkup and Security Checkup instead. That is a fair summary of the limits of the category: an alert is only useful if there is a clear action attached to it.

Free Options That Cover Most Small Businesses

Have I Been Pwned

Have I Been Pwned is a long-running breach lookup service. Anyone can search an email address and sign up for free notifications about future breaches. For a business, the useful feature is domain search: after you prove you control your domain, it lists every address at that domain found in a breach and notifies you of new ones.

As of September 2026, Have I Been Pwned’s pricing page shows domain monitoring is free for domains with up to 10 breached addresses. Above that, paid plans start at $4.39 per month for one domain with up to 25 breached addresses, and $21.59 per month covers three domains with up to 100 breached addresses each. Stealer log data for a domain is included only in the Pro plans, which start at $379 per month, so the affordable tiers cover breach data but not infostealer data.

Microsoft 365: Leaked Credentials Detection

If your business uses Microsoft 365, Microsoft already does a version of this for your work accounts. According to Microsoft’s documentation, its leaked credentials detection monitors “dark web forums, breach dump repositories, paste sites, law enforcement seizure data, and other sources,” then checks what it finds against your users’ current valid passwords. It raises a detection only on a confirmed match, which avoids alerts about passwords nobody uses anymore.

Microsoft lists this detection as available with Entra ID Free and Entra ID P1. Entra ID is the sign-in system behind Microsoft 365, and P1 is included in Microsoft 365 Business Premium. There is a catch. With Free or P1, the Risky users report shows limited information, and email alerts and automatic responses require Entra ID P2. In practice, someone has to open the report on a schedule. P2 is part of the Microsoft Defender Suite add-on for Business Premium, listed at $10 per user per month, paid yearly, as of September 2026. Our guide to Microsoft Entra ID for small business explains the plans.

Browser and Password Manager Checks

  • Microsoft Edge Password Monitor checks passwords saved in Edge against known leaks and is turned on automatically for people who are signed in and syncing passwords.
  • Google Password Checkup flags saved passwords in Google Password Manager that are compromised, reused, or weak.
  • Business password managers usually include a breach report. 1Password calls its version Watchtower, for example. This has the advantage of checking the passwords your staff actually use for business accounts.
  • For owners personally: Microsoft 365 Personal and Family subscriptions in the United States include identity theft monitoring in Microsoft Defender. It covers personal information, not your company domain.

What Should You Do When a Credential Shows Up?

Work through these in order. For a routine breach alert, allow roughly 15 to 30 minutes per account.

  1. Identify the source and the date. A breach at a third-party website in 2019 is different from a stealer log collected last month.
  2. Ask whether that password is still in use anywhere. Check the person’s work account and any other service where they might have reused it. If yes, change it everywhere it was used, to a unique password from a password manager.
  3. Sign the account out of all sessions after the reset, so that any stolen session stops working.
  4. Confirm MFA is on for that account. If it was not, this is the fix that matters most. See why multi-factor authentication matters.
  5. Review recent sign-ins for unfamiliar locations or devices, and check the mailbox for forwarding rules or connected apps that the person did not set up.
  6. If the source is infostealer malware, treat the computer as compromised. A stealer log means malware ran on a device. Find the device, have it cleaned or rebuilt, and reset every password that was saved in its browser, not only the one in the alert.
  7. If you find signs of actual access to email or files, move to an incident process. Our guide on what to do after a data breach covers the steps and the notification rules.

An alert for an old breach where the password was changed long ago and MFA is on usually needs no action beyond noting it.

When Does a Paid Service Make Sense?

A paid dark web monitoring product can be reasonable when:

  • Your domain has more breached addresses than the free tier allows and you want ongoing alerts
  • You want coverage of stealer logs, which the low-cost tiers do not include
  • A cyber insurance application or a customer security questionnaire asks whether you monitor for exposed credentials
  • You want one report across several domains

Questions to ask any vendor:

QuestionWhy it matters
Which sources do you cover: public breaches, stealer logs, private forums?Coverage varies, and no vendor sees everything
Do alerts include the date and origin of the data?Without them you cannot judge urgency
Do you check whether the exposed password is still valid?This separates useful alerts from noise
How are alerts delivered, and who is expected to act on them?An unread alert has no value
What does it cost per domain or per user, and what is the contract length?Compare against the free options above

When You Do Not Need to Pay for It

If MFA is enforced for every account, staff use a password manager with unique passwords, and someone checks the free Have I Been Pwned domain report and the Microsoft 365 risky users report on a regular schedule, a separate paid subscription adds little. Spend the money first on the controls that stop a stolen password from working. Our small business IT checklist lists those basics.

Common Mistakes

  • Treating every alert as an emergency. Check the date and whether the password is still in use before acting.
  • Resetting one password and stopping. If the password was reused, every copy needs to change. If malware was the source, the device needs attention too.
  • Buying monitoring before turning on MFA. Monitoring reports exposure. MFA limits what an exposed password can do.
  • Nobody owns the alerts. Decide who reads them and what they do next, and write it down.
  • Judging a free scan by the number of results. A long list of old third-party breaches says little about your current risk. What matters is whether any of those passwords still open anything.

Common Questions

Is dark web monitoring worth it for a small business?

As a free or low-cost add-on, yes. As a main security investment, no. It gives early warning about exposed passwords but does nothing to stop them being used. MFA on every account and unique passwords from a password manager reduce the risk directly, and monitoring then tells you which passwords to rotate.

Can stolen data be removed from the dark web?

No. Once data has been copied and traded, there is no reliable way to delete it. Be cautious about any service that says otherwise. What you can do is make the data useless by changing the exposed password, turning on MFA, and, for personal identity information, placing credit freezes, which the FTC notes are free to place and lift.

Does Microsoft 365 include dark web monitoring?

In part. Microsoft Entra ID includes a leaked credentials detection that compares credentials found in criminal sources against your users’ current passwords, and Microsoft lists it as available without a P2 license. Without Entra ID P2, reporting is limited and there are no email alerts, so an administrator needs to review the Risky users report manually.

Does Google still offer a dark web report?

No. Google stopped scanning in January 2026 and removed the dark web report from consumer accounts in February 2026. Google directs people to Password Checkup, which flags compromised, reused, and weak passwords saved in Google Password Manager, and to Security Checkup for the account itself.

A work email appears in a breach. Was the company hacked?

Usually not. Most results mean that another company where you had an account was breached, and your address was in its customer list. It matters for your business only if the password exposed there is also used for a work system. A result sourced from stealer logs is different and points to malware on a device.

How Coastal Growth Co. Can Help

We can set up free domain monitoring for your business, show you where the Microsoft 365 risky users report lives, and agree on who reviews both and how often. When something shows up, we can work through the response steps above with you, including checking sign-in logs and cleaning an affected computer. This fits within managed IT support or as a one-time review, with scope and price agreed first. Reach us through the contact page.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.