All professional firms
Your firm's passwords are on the dark web. Now what?
· PS ProTech · 2 min read
"Your credentials have been found on the dark web" sounds alarming, and it's meant to. Here's what it means in plain terms, and what to do about it.
What the dark web is
It's a part of the internet that needs special software to reach and is built to hide who is using it. Among other things, it's where stolen information is bought, sold and given away. Lists of email addresses and passwords are the most common item on offer.
How your firm's passwords got there
Almost never because your firm was broken into. The usual route is this:
- Someone at your firm signed up for another service with their work email: a hotel site, a conference, a retailer, a professional forum.
- That service was breached, and its list of emails and passwords was stolen.
- The list was sold or published.
Your firm did nothing wrong. But a work email address and a password that person once used are now in criminal hands.
Why it matters
People reuse passwords. Attackers know this, so they take every email and password from a stolen list and try the pair on the services that matter: Microsoft 365, Google, banking, payroll. It's automated, and they try millions.
If your colleague used the same password for the conference site and for work email, the attacker is now in their mailbox. From there they can read client correspondence, reset other passwords, and send email as that person. Most of the payment fraud we describe in wire fraud at closing starts exactly this way.
What to do when you find out
1. Change that password everywhere it was used. Not only on the breached site. The work account first.
2. Check the account for signs of misuse. Sign-ins from unfamiliar places, new forwarding rules in the mailbox, sent messages nobody remembers sending.
3. Make sure multi-factor authentication is on. With it, the stolen password isn't enough. This is why MFA is the first thing to fix.
How to stop it mattering
You can't prevent other companies from being breached. You can make their breaches harmless to you.
- A different password for every service. Nobody can remember that many, so use a password manager.
- Multi-factor authentication on everything important.
- Work email for work only. The fewer outside sites hold it, the less it leaks.
- Monitoring, so you hear about a leak in days and can act before the password is tried.
What monitoring does
A dark web monitoring service watches stolen data for addresses at your firm's domain and alerts you when one appears, with the service it came from where that's known. It doesn't remove anything, since nothing can. What it gives you is time to change the password first.
It's included from our Business plan, and it's item three on the security checklist. To find out where your firm stands, book a free IT and cybersecurity review.
