Every major data breach brings a fresh wave of companies selling “dark web monitoring,” and they show up with the predictability of vultures. Millions of records hit the news, and within hours your inbox fills with offers to scour the internet’s underbelly and alert you the moment your data surfaces on some hacker forum. The marketing is slick. The dashboards look serious. The pitch is real-time protection against the worst people online.

It is also, by any honest measure, close to useless. This is a multibillion-dollar industry built on security theater and a monthly subscription to your own anxiety.

What the monitoring actually does

The marketing describes digital vigilantes. Sophisticated algorithms and expert analysts, working the shadows around the clock, watching underground marketplaces and criminal databases for your email addresses, passwords, social security number, card numbers, driver’s license, even your medical records. It’s a compelling picture, and almost none of it is what you’re buying.

What you’re buying is a script. It checks a handful of publicly accessible breach databases and paste sites, many of which aren’t even on the dark web but on the ordinary internet with a .onion mirror bolted on for the brochure. It looks for exact string matches against the data you handed over, which means the service asks you to surrender the very information you’re anxious about so it can go looking for it. And when it finds a hit, it tells you, with the urgency of a fire alarm, something you almost certainly already knew: that your address from a years-old breach is still sitting in the same compilation dump that’s been passed around a dozen torrents. You paid for a search engine pointed at the least valuable copy of your data.

Reactive is fatal, and the timing is why

The deeper problem is the timing, and it’s not a small one. By the time your information appears anywhere a monitoring service can actually see it, the useful life of that data is over. It has already been exfiltrated, sorted, validated, priced, sold to people who paid for freshness, and worked for whatever it was worth. The public dump is the exhaust, not the event.

Walk the lifecycle. First the breach: someone quietly pulls the data out, often weeks or months before anyone notices, sometimes before the victim company itself knows. Then processing: the raw dump gets deduplicated, validated against live logins, enriched with other breaches so a bare email becomes a full profile with password, phone, address, and answers to your security questions. Then the private sales, which is where the money is. Fresh, validated records with working credentials go to trusted buyers through vetted channels, sold in tranches, sometimes to a single buyer who wants exclusivity. Only after all of that value has been extracted does the remainder get dumped publicly, either to build a seller’s reputation or because it’s simply spent.

Public exposure is the last stage, not the first. A monitoring alert isn’t an early warning; it’s a receipt. It tells you the burglary happened, the goods were fenced, the buyer already used them, and now the empty boxes are showing up at the curb. Whatever was going to be done with your data was done long before any dashboard lit up. That’s the part the marketing can’t say out loud, because the entire product is built on watching the one place the data arrives last.

The coverage is worse than incomplete

Even setting aside the timing, the map is wrong. The “dark web” isn’t a single place with a directory and a search box. It’s a moving target: thousands of forums that shift and die, private Telegram channels with invite links that rotate faster than anyone can index them, Discord servers that live for a few days and vanish, invite-only marketplaces that demand proof of criminal activity before they let you in, and a great deal of trade that happens one-to-one inside encrypted messaging where there is nothing to crawl at all. The most valuable transactions are, by design, the least visible. No service covers a meaningful fraction of it, and the fraction it does cover is precisely the part where nothing valuable happens anymore.

The economics reinforce this. Stolen data is priced like produce, on freshness. New records with verified logins command real money. A month later they’re discounted. A year later they’re loss leaders, bundled and given away to draw buyers to the fresh stuff. So the data a monitoring service can “discover” is, almost by definition, the data nobody is willing to pay for. You’re paying a monthly fee to be told that your old password is in a dump everyone has already seen, which you could have checked against Have I Been Pwned for free, once, in ten seconds.

The alert you can’t act on

Say the notification does arrive. Three in the morning, your social security number was found on the dark web. Now what? You can’t change your SSN. You can’t reach into a criminal forum and delete the record. The data has already propagated to a dozen places you’ll never find. A traditional monitoring service has walked you to this point and has nothing to offer past it except the alert itself. The whole product ends at the moment you actually need it to do something.

There is one response that does something, and it’s the reason I got into this. You buy the data back and take it out of circulation. Instead of watching a copy surface, you go to the source, acquire the record, and remove that particular copy from the market before it’s resold again.

Legally, this is more interesting than it sounds, because on its face it looks like paying criminals, and most companies won’t go near anything that resembles that. In February 2020 the U.S. Department of Justice published Legal Considerations when Gathering Online Cyber Threat Intelligence and Purchasing Data from Illicit Sources, which lays out how an organization can engage with illicit markets to buy back data and gather intelligence without crossing into criminal liability. The guidance existed. The legal path was real. Almost nobody used it, because it required doing genuinely hard operational work: maintaining access to closed communities, moving through those channels credibly, handling the counterparties, and doing all of it inside the lines the DOJ drew. Running a script against a public paste site is cheap and scales to millions of customers. Actually retrieving someone’s data is expensive, manual, and doesn’t fit a $12 monthly plan. To my knowledge my startup, MINDWISE, was the only service that actually did it.

Why fear is the better business

Once you see the gap between what these services promise and what they do, the obvious question is why the industry looks like this. The answer is that fear is simply a better product than security.

Security is invisible when it works. Nobody feels protected by a breach that didn’t happen or a credential that was never resold, so there’s nothing to renew against. Fear is the opposite. It’s felt, it’s recurring, and it renews itself with every headline. A monitoring subscription doesn’t sell you an outcome; it sells you the feeling of doing something, billed monthly, and the news cycle handles the marketing for free. That’s a durable model precisely because it never has to resolve the anxiety. If the fear went away, so would the revenue, so the product is designed to keep you subscribed and afraid rather than to make the problem go away.

The pitch works because it sits on top of three real things. Data breaches genuinely happen and genuinely ruin lives, so the underlying fear is legitimate. Most people don’t understand what the dark web is or how fraud actually moves, so the mechanism can be described however the seller likes. And in a world where breaches feel inevitable, the promise of any agency at all is worth paying for, even when the agency is fictional. Charge ten to thirty dollars a person for automated searches of already-public dumps, wrap it in a weekly report that sounds alarming, and you have a business that runs on the one emotion that never runs out.

The scamification pipeline

None of this is unique to cybersecurity. It’s a general pattern, and once you can see its shape you start noticing it everywhere, from personal finance to health to privacy. The move is always the same: find a real fear, amplify it past its actual likelihood, offer a shiny and reassuringly branded solution, lock it behind a subscription, and deliver just enough value to stay clear of an outright fraud claim while never touching the underlying problem.

Each step depends on the one before it. It starts with a real fear because a fabricated one won’t hold; data breaches and identity theft do real damage, and that kernel of truth is what makes the rest credible. The amplification pushes an ordinary risk toward the worst case, because a calm and accurate description of the odds doesn’t sell. The shiny solution has to feel modern and effortless, because friction breaks the spell. The subscription is where the actual genius lives, since recurring revenue turns a one-time worry into an annuity. And the deliberately thin value is what keeps the whole scheme standing: do too little and customers notice, do too much and you’ve solved the problem you needed to keep selling against.

It works for reasons that have nothing to do with the specific product. People fear what they don’t understand, and almost nobody understands the machinery of data brokers and fraud. People want control, and these services sell the shape of control without the substance. The complexity of modern technology leaves most people feeling outmatched and ready to hand the problem to anyone who sounds confident. And underneath all of it, the systems that should actually protect us mostly don’t, which leaves a wide-open market for the appearance of protection.

What actually works

The genuinely useful measures are unglamorous, they don’t come with a dashboard, and most of them are free. That’s exactly why nobody runs ads for them.

  • Use a password manager, with a unique password for every account.
  • Turn on 2FA everywhere it’s offered, and use an authenticator app rather than SMS.
  • Freeze your credit if you aren’t actively applying for anything.
  • Watch your actual financial accounts, since that’s where fraud shows up in a form you can act on.
  • Treat unsolicited messages, calls, and emails as suspect by default.
  • Keep your software and devices updated.
  • Keep your email tidy: separate addresses for separate purposes, and don’t reuse the important one everywhere.

Every one of these prevents harm instead of narrating it after the fact, which is the difference between security and theater.

The bottom line

Traditional dark web monitoring is a solution hunting for a problem it can solve, and it hasn’t found one. It’s the cybersecurity version of the extended-warranty robocall: it runs on fear and confusion, extracts a monthly fee, and leaves you roughly where it found you.

Your data is almost certainly already out there. If you’ve been online for more than a few years, some slice of your personal information sits in some criminal database right now. That’s not pessimism, it’s arithmetic. But being exposed and being powerless are different things. The useful response was never to pay someone to watch the data arrive. It was to reduce what a stolen record can actually do to you, and, when it was possible, to go get the data back.