Skip to main content

Dark web

What is the dark web and how does it work?

What is the dark web and how does it work

Summary: The dark web is used for illegal activities like selling stolen data or accessing restricted content. Learn how it works and how to protect your data.

The dark web was designed to provide anonymity. While it has legitimate uses, such as ensuring privacy, facilitating journalism, and granting access to information in censored countries, it’s also a place where criminal activity happens, and almost anything is available for a price. Stolen data, contraband, and cybercrime services change hands out of sight. Some estimates suggest dark web markets handle around $1.7 billion annually.

For companies, it’s where breached credentials, customer records, and access to internal systems can quietly be put up for sale. So, how can you defend against that risk? First, try to understand what the dark web is and how it works.

Key takeaways

  • The dark web includes web content that search engines can’t access and that users can’t reach with standard browsers.
  • Dark web content differs from the surface web which is accessible through search engines and browsers, such as Google. The deep web is not indexed by search engines but can be accessed with regular browsers. The dark web is not accessible without the Tor browser or a similar tool.
  • The dark web first sought to avoid censorship and ensure privacy It later became associated with crime as anonymous marketplaces and cryptocurrencies grew. Law enforcement agencies routinely close markets, but buying and selling continue.
  • Goods available on the dark web often include drugs, counterfeit medications, weapons, and stolen data. Users can purchase any illegal item using anonymous payment methods. Many buyers are cybercriminals who want to use stolen personal data to access bank accounts or company networks.
  • Keep data away from dark web sellers through layered controls Security measures include using a business VPN, implementing strong password policies, and controlling network access Businesses should also use dark web monitoring to detect potential data breaches early and reduce risks.

What is the dark web?

The dark web is a hidden and intentionally concealed part of the internet that standard search engines cannot find. It consists of websites whose owners keep them unindexed and that sit on encrypted networks. You won’t reach them by typing a query into Google or clicking a normal link from your browser.

The dark web is a small subset of the broader deep web. Deep web pages are also unindexed, but you can reach them through regular browsers if you have the correct login information and URL (e.g., online banking portals, SaaS admin dashboards, or internal HR tools). Dark websites, by contrast, run on overlay networks, such as Tor. Within the Tor network, websites use special .onion addresses that can only be accessed through compatible software, such as the Tor Browser.

Access usually requires tools like the Tor browser (the Onion Router) Tor routes traffic through multiple volunteer-run relays and wraps it in layers of encryption which makes it much harder to link your online activity to your real IP address. This design helps conceal both visitors and the services they access.

In practice, the dark web has 2 faces One is a marketplace for stolen data, malware, illegal drugs, weapons, and cybercrime as a service. The other is a privacy layer used by journalists, whistleblowers, activists, and ordinary citizens who need to bypass censorship or avoid tracking and retaliation. From a defender’s perspective, both sides matter: the same anonymity that protects dissidents also shields cybercriminals who trade access to your systems

How does the dark web work?

The public internet (or surface web) is made up of visible servers and web content identified by public IP addresses.

The dark web also contains server-hosted content, but its sites run on overlay networks, such as Tor, and require specific software to access. These sites often use non-standard addresses, such as .onion domains, which regular search engines cannot crawl or index in the same way as websites on the open web.

Much of the web’s content is not indexed by search engines. This includes data behind password-protected portals, private databases, obsolete files, and other content that search engines cannot or do not crawl. However, only a small part of this unindexed content belongs to the dark web.

To be part of the dark web, sites must be invisible to standard web browsers and search engines.

How the dark web ensures anonymity

The dark web relies on non-standard protocols and encryption techniques. Dark web browsers like Tor use special protocols to generate encrypted entry points. These protocols use a layered encryption model that wraps data packets in many layers.

Tor also plots complex pathways for dark web data. As data passes between nodes, the layers of encryption peel away, like the skin of an onion. This process leaves no traceable connection between the entry point and the destination. Users remain anonymous as long as Tor is operating; however, Tor provides strong anonymity, not absolute untraceability

Tor differs from standard browsers in other ways, too. For example, your internet service provider (ISP) can usually see that you’re connecting to the Tor network, but it can’t see which sites you visit or what content you access through Tor The Tor Browser also clears cookies and browsing data after each session and limits features that could expose identifying information, such as location data.

How does the dark web work

Standard browsers can access most internet content, even if it does not appear in Google search results. The dark web is different.

Experts estimate that the dark web comprises only a small amount of unindexed content.

How do you find sites on the dark web?

Because dark websites are intentionally hidden, you can’t “Google” your way to them. Internet users usually find dark web content in 3 main ways:

  1. Direct .onion addresses
    Most dark web services share their URLs (.onion addresses) in invite-only forums, encrypted chats, or paste sites. These addresses are long and random, so users typically copy and paste them or store them in password managers. If the URL changes or the market disappears, the site is effectively gone unless its operators push out a new address.
  2. Dark web directories and link lists
    Community-maintained directories act like rough catalogs for .onion services and group links by topic (e.g., markets, forums, whistleblower platforms, etc.). However, because dark websites change quickly, many directory entries are outdated or dangerous. For this reason, security teams treat public link lists with caution and instead rely on curated threat intelligence feeds.
  3. Dark web search engines
    There are search engines on the dark web, but they work very differently from Google:
    • Torch, Haystak, and Not Evil, along with similar crawlers try to index large portions of the Tor network, but coverage is patchy, and results often include spam, clones, or dead markets.
    • Ahmia focuses on safer results and filters out some abusive content. It also publishes a clear policy on what it indexes and what it blocks.
    • Some privacy-focused search engines (such as specific Tor-hidden mirrors of DuckDuckGo) provide a familiar search box inside the Tor network, yet they still only reach a fraction of hidden services.

Even with these tools, search is unreliable. Many results point to seized markets, phishing clones, or malware droppers. That’s one reason businesses rely on professional dark web monitoring and threat exposure platforms instead of manually searching dark web engines.

Differences between the surface web, deep web, and dark web

Before we go further, let’s clear up a common misconception by defining some key terms. We can’t talk about the dark web without first understanding how it differs from the surface web and the deep web.

surface web deep web dark web

The surface web

The surface web is the outer layer of the internet that web browser users see. When you run a Google query, the search engine delivers results from the surface web.

Algorithms process indexed data, assessing its relevance and quality. However, in the process, search engines miss a lot of data. Ideally, this doesn’t matter because indexers collect the most relevant information and ignore everything else.

For example, Google might return a set of Amazon landing pages in response to a query about sports jackets. These searches won’t include back-end metadata or private vendor pages that require passwords. Users only see publicly accessible product listings.

The surface web represents only a portion of the internet though estimates of its exact size vary widely depending on how researchers define and measure web content.

The deep web

The deep web is made up of internet data that is not indexed by search engines. Deep web data is not really “hidden” from ordinary browsers. Content may only be accessible with login credentials, but you don’t need Tor or similar layered encryption tools.

Deep web content includes data stored behind login portals or paywalls. Social media profiles are a good example. However, most deep web content is ordinary website data like unused or outdated files. Site owners use the robots.txt files to tell search engine crawlers which pages or sections of a site they should not crawl.

The deep web makes up the majority of web content because it includes everything from private accounts and databases to pages that search engines do not index. Its exact size is difficult to measure.

The dark web

The dark web is a subset of the deep web that exists in the shadows This hidden part of the web features everything we cannot see without special tools.

Because of this, measuring dark web traffic is almost impossible. The same applies to monitoring dark web criminal activity. It’s hard to know whether your personal data is being sold online. Companies cannot tell when hackers coordinate on the dark web to plan attacks.

Surface web

Deep web

Dark web

Indexing

Yes, it is indexed by search engines

No

No

Accessibility

Standard browsers

Standard browsers with a login or link

Special software required

Common domain

.com, .org, .net, .gov

.com, .org, .net, .gov, with additional authentication

.onion

Estimated size of the Internet

A smaller share of web content

The majority of web content

A small subset of the deep web

Primary content

Publicly available information

Private, secured, dynamic data (email, online banking, cloud storage, medical records, company intranets)

Anonymous sites, dark web markets, whistleblower platforms, forums, political dissent sites, and illegal content

Legality

Yes

Yes

Legal to access, but it hosts many illegal activities

When was the dark web created?

The dark web began in 1999 in the research lab at the University of Edinburgh with a student named Ian Clarke. As part of his computer science degree, Clarke wrote a landmark paper titled “A Distributed, Decentralised Information Storage and Retrieval System.”

In 2000, he released a working version of the project, called Freenet Clarke’s goal was to give members of the public total anonymity. As concerns about online privacy and government censorship grew, Freenet became the next logical step. Nobody called it the “dark web,” at least not yet.

US intel agencies made the next leap forward, releasing the Tor network in 2004. Scientists at the Naval Research Laboratory (NRL) created Tor to support anonymous intelligence and battlefield activity. However, the creators successfully argued for its public release.

They realized that the network’s decentralized routing and layered encryption needed a large community of users. That’s why they launched the Tor Project and refined the Tor browser in 2008.

Tor could not function without a large user community, even if that meant the government losing control, which is exactly what happened.

In 2009, a little-known website called Silk Road started to make headlines. Based on the dark web, Silk Road grew as cryptocurrencies expanded. Dark web marketplaces soon sold everything from drugs and firearms to pornography, pirated software, and prescription medication.

The FBI arrested Silk Road founder Ross Ulbricht in 2013 and closed the site, but the dark web remains a busy marketplace. Silk Road 2.0 appeared immediately, followed by Diabolus Market and OpenBazaar.

The dark web has also become notorious for more than illegal goods. A 2022 study found 24.6 billion pairs of credentials available for purchase. The dark web now functions as a brokerage for credentials providing access to vast private databases.

Threat actors obtain passwords through data breaches. Other criminals buy stolen data to use in phishing attacks and other cybercrimes. Prices are easily affordable with credit card details selling for around $120 and single passwords costing just $10. It’s a cybersecurity nightmare.

Why does the dark web exist?

Given the criminal activity associated with the dark web, it’s natural to ask why it exists. Scientists developed the underlying technology with noble purposes in mind. Neither the NRL nor Ian Clarke ever intended to encourage crime, but their creations made the dark web possible.

The dark web’s creators set out to protect individual privacy. By the late 1990s, early enthusiasm about the internet had given way to fears about crime and surveillance. People needed ways to browse and communicate anonymously. Tor and Freenet were effective solutions.

The dark web is still a valuable privacy tool. Media organizations such as the BBC, The New Yorker, and ProPublica use dark web tools to support censorship-free browsing in repressive countries.

Is the dark web illegal?

No, it’s not. While going to the dark web and using dark web tools are legal, using the dark web to commit criminal acts is not.

The benefits mentioned earlier are probably why the dark web remains legal and supported by some governments Tor is one of the most reliable ways to evade authoritarian surveillance

Balancing anonymity with the risk of credential theft and illicit sales is hard, but most governments prefer the legal route.

Note Some countries, including China and Russia, block or restrict access to the Tor network. Restrictions and enforcement vary by country, so check local rules before using Tor while traveling.

How people access the dark web

From a technical point of view, accessing the dark web usually involves 3 steps:

  1. Install a specialized browser
    The most common option is the Tor Browser, which you can download from the official Tor Project website. This browser comes with the software needed to connect to the Tor network and is preconfigured with safer defaults (for example, blocking certain plugins and trackers).
  2. Connect to the Tor network
    When Tor launches, it builds an encrypted route through several relays before you reach any site. In some countries where Tor is restricted or blocked, users may need extra configurations, such as “bridges,” and should check the local laws before trying to connect.
  3. Open dark web services via their addresses
    Once connected, you can enter .onion URLs or use dark web search engines and directories to reach hidden services. Unlike normal web browsing, there’s no guarantee that a site is legitimate, legal, or safe to visit. Visiting illegal content or buying illicit goods is a crime in most jurisdictions, even if the connection itself runs over Tor.

Experts recommend that anyone who needs to access the dark web for research or security reasons do so only on hardened, isolated systems, with strong endpoint protection, business VPN use where legal, and clear internal policies about what staff may and may not do.

What can be found on the dark web?

Dark web markets borrow many tricks from ordinary e-commerce sites: product categories, search filters, seller ratings, and even customer support. The difference is the inventory, which ranges from stolen data and access credentials to forged documents and cybercrime services.

Recent dark web price-index reports from Privacy Affairs, Experian, Nord Security, and others show that much of this data is cheap, even in 2025–2026.

What dark web marketplaces look like

Dark web marketplaces use escrow services, where payments are held by the marketplace until the buyer confirms that they received the product or service. Buyers and sellers may communicate through encrypted channels, including PGP-encrypted messages that protect message content and transaction details.

However, these marketplaces are far less stable and more dangerous than normal online platforms. They can disappear overnight because of law enforcement operations, security breaches, or exit scams, in which marketplace operators suddenly close the marketplace and steal users’ funds. This uncertainty is one reason why dark web activity moves between platforms.

Dark web price snapshot (2025–2026)

Typical listings on dark web markets currently include:

  • Credit card details From around $8 for an American Express card to $12 for a Mastercard. Over 70% of all card listings on the dark web are from the US.
  • Online banking logins Access to an account with a minimum balance of ~$2,000 often costs around $60 High-value bank or payment accounts (e.g., Stripe or Revolut) can run from several hundred dollars to over $4,000
  • PayPal and similar wallets PayPal credentials with spendable balances frequently appear for around $100 with some “money transfer” offers priced per transaction.
  • Cryptocurrency accounts and wallets Logins for crypto services range from $20 to $350 in many recent reports, while verified or high-balance exchange accounts can reach $2,500+
  • Business and consumer credentials Bank statements, utility bills, VPN accounts, and health insurance cards often list for around $10–$15 each, making them useful as building blocks for identity theft or social engineering.
  • Email and social media accounts A hacked Gmail inbox averages about $55 while hacked Facebook, Instagram, Telegram, Snapchat, TikTok, or Twitter/X accounts often sell for $33–$88 per profile, depending on the social media platform.
  • Streaming and subscription services Compromised logins for Netflix, Hulu, Spotify, or Disney+ can cost anywhere from $5 to $32 for basic accounts, $130 for Airbnb accounts, and up to $300 for high-value and verified profiles.
  • Bulk email lists Datasets containing 10 million US email addresses for example, often sell for around $120 per dump, feeding phishing campaigns and credential stuffing.
  • Identity documents Templates and scans of passports, identity cards, and driver’s licenses start at about $63–$150 while high-quality forged or stolen passports in some markets average over $2,000 with driver’s licenses in the hundreds of dollars
  • Cybercrime tools and services Malware “install” packages are often sold by the thousand infected devices, while a one-week DDoS attack on an unprotected site (10,000–50,000 requests per second) is still advertised at around $350 on some platforms.

Prices change constantly based on supply, demand, and law-enforcement pressure. But the pattern stays the same. Highly sensitive data and attack services are cheap enough for almost any cybercriminal. That is why even small companies should assume their data could end up on the dark web and put strong controls in place to reduce that risk.

Types of threats on the dark web

The dark web may be legal, but it’s not safe Many critical threats make the dark web dangerous. Here are a few of the most concerning examples:

  • Illegal activity When users access the dark web, it’s easy to become involved in criminal activities. Dark web marketplaces sell illicit drugs, firearms, and even stolen information like medical and legal documents. Buying stolen or prohibited items carries the risk of legal consequences.
  • Malicious software The dark web is unregulated. Dark web forums you visit could direct you to malware and compromise your device. They could also direct you to illegal content without warning. Links may lead to malware or harmful and illegal content, and their destination can be difficult to verify in advance.
  • Hacking Dark websites are hangouts for data thieves and other hackers. These actors are happy to target customers and casual dark web visitors alike.
  • Ransomware as a service (RaaS) Dark web vendors now sell off-the-shelf ransomware kits, allowing anyone to launch ransomware attacks. Groups such as Qilin and the Gentlemen provide specialized software that uses stolen data.
  • Webcam attacks One of the scariest dark web hazards is webcam hijacking. Attackers target visitors with unsecured cameras. They may then deploy remote administration tools to blackmail their victims or gather data from the camera.
  • Data breaches The dark web is a global hub for the origin and trade of data breaches. Nobody is safe. For instance, in March 2024, communications giant AT&T reported a data breach involving 73 million records. The stolen data has been available on the dark web since 2019. And AT&T is just the tip of the iceberg.
  • Law enforcement Criminality is everywhere on the dark web, but so is law enforcement. Users who engage in illicit behavior risk detection and prosecution. Never assume that contacts are who they say they are.

Is your business data on the dark web?

There are some positive uses of the dark web, but you need to be aware of the dangers. Most importantly, every internet user and company must know if their data is available on the dark web and have ways to prevent it from being there.

Let’s start with a simple process to check whether your information is on the dark web.

First, don’t enter the dark web alone Individual users lack the context and tools to search dark web sources effectively. Simply logging in to Tor and looking for your name won’t work.

Companies worried about leaked credentials can use NordLayer Intelligence a threat exposure management platform with dark web monitoring capabilities.

Dark web monitoring solutions use huge databases of exposed credentials. Scanners constantly analyze databases of compromised credentials and scan dark web forums and marketplaces for keywords related to your business data.

How to keep your company data off the dark web

Searching the dark web for confidential data can be imprecise. A smarter approach is to prevent the disclosure of your company’s data in the first place

Dark web criminals are skilled and ruthless, but cybersecurity measures deter even the most determined data thieves However, many companies fail to put those barriers in place. That’s why dark web markets stay busy, but it doesn’t have to be like that.

Here are some tips to secure your data and ruin the bottom line of dark web data vendors:

  • Protect traffic with a business virtual private network (VPN) Use a business VPN to encrypt traffic and secure remote access to company resources.
  • Guard your credentials. Credential theft or brute force attacks allow criminals to access your network and steal user or customer data. Enforce strong, regularly changed passwords. Add multi-factor authentication for all logins. Apply zero-trust principles to minimize access to sensitive data.
  • Be smart about phishing Phishing tricks users into clicking on dangerous links, leading to malware infections and data loss. Use advanced DNS filtering solutions to prevent access to websites used in phishing attacks. Train employees to spot phishing emails and explain why phishing awareness is a critical data protection issue.
  • Use dark web monitoring Dark web monitoring is a must-have for companies handling sensitive data. Remember the AT&T case? It took 5 years to uncover the data breach, resulting in millions of dark web sales. Monitoring alerts you about data exposure quickly. It also helps you improve your security and prevent cyberattacks.
  • Put in place layered threat protection Don’t apply password security, VPN coverage, and access controls on their own. Bring everything together in one platform, such as NordLayer. That way, you can anticipate and neutralize threats before they cause problems.

The tips above will protect companies that do not intend to access the dark web.

But what if you need to use the dark web safely? In that case, extra data security measures are necessary.

  • Be very cautious about exposing confidential information on dark web forums. Never mention your name, employer, phone number, or address.
  • Never trust dark websites Onion services can use HTTPS certificates, but they do not guarantee that a site is legitimate or trustworthy. Be careful when sharing information, joining discussions, or making purchases.
  • Don’t click on links in forum posts Dark web links can easily be malicious or lead you to illegal content. As a rule, avoid clicking on unknown links whenever possible.
  • Consider increasing Tor Browser’s security level to restrict JavaScript and other potentially risky web features.
  • Separate dark web browsing from critical assets Ideally, only use Tor inside a well-defended network segment. Create a secure zone with minimal east-west movement. If the worst happens, this should reduce the damage.

Senior Cybersecurity Copywriter

Share this post

Related Articles

Stay in the know

Subscribe to our blog updates for in-depth perspectives on cybersecurity.