Dark Web Monitoring
Dark Web Monitoring checks your managed users' email addresses against the HaveIBeenPwned (HIBP) database to detect when credentials or sensitive data appear in known data breaches or paste sites.
Dark Web Monitoring is included in the User Protection package at $3/managed user/month.
How It Works
- You add email addresses to monitor (manually, via M365 sync, or CSV import)
- The HIBP scanner runs automatically every 12 hours against the HIBP API v3
- New breach findings appear as New status in the Breach Findings table
- Your team acknowledges and resolves each finding
Adding Monitors
Navigate to SecOps → Dark Web Monitoring and click Add Monitor.
| Monitor Type | Description |
|---|---|
| Email (HIBP) | Checks email against HIBP breach and paste databases |
| Domain | Monitors for a domain appearing in breach data |
| Keyword | Monitors for a specific keyword |
On-Demand Scanning
Click Check HIBP on any individual email monitor to run an immediate scan outside the automated schedule.
Summary Metrics
The Dark Web Monitoring dashboard shows:
| Metric | Description |
|---|---|
| Monitored Emails | Active email monitors |
| Total Breaches | All breach findings across all monitors |
| New Breaches | Findings not yet acknowledged |
| Critical Exposures | New findings rated Critical severity |
Breach Findings
Each finding includes:
| Field | Description |
|---|---|
| The monitored email address found in the breach | |
| Breach Name / Paste Source | The breach or paste site where the email appeared |
| Data Exposed | Types of data in the breach (emails, passwords, phone numbers, etc.) |
| Password Exposed | Boolean flag — highlighted in red if passwords are in the breach |
| Severity | Critical (password exposed) / High / Medium / Low / Info |
| Breach Date | When the original breach occurred |
| Status | New / Acknowledged / Resolved / False Positive |
Breach Detail Panel
Click any finding to open the detail panel. For breach-type findings, it shows:
- Breach title and domain
- Account count (how many total accounts were in the breach)
- Data class breakdown
- Verified / Sensitive flags from HIBP
For paste-type findings, it shows:
- Paste source (e.g., Pastebin)
- Paste title and email count
- Paste URL
Acknowledge / Resolve Workflow
| Action | When to Use |
|---|---|
| Acknowledge | You've seen the finding and are investigating — moves status from New to Acknowledged |
| Mark Resolved | Remediation complete (e.g., password reset, user notified) — moves to Resolved |
Findings can also be marked False Positive if the match is incorrect.
Filtering Findings
Use the status filter buttons to view: New | Acknowledged | Resolved | All
The default view shows New findings — the items requiring immediate attention.