A simple definition
The dark web is a portion of the internet that doesn't show up in standard search engines and requires specific software to access, originally designed to protect its users' anonymity. The vast majority of its use has nothing to do with crime. But part of it serves as a marketplace for actors who buy and resell stolen data — that's the part this report documents, without explaining how to access it.
What's actually traded there
According to Europol's annual cybercrime assessment (2025), the online criminal economy runs above all on access: access to accounts, to identities, to sensitive information. Login credentials, card numbers, medical records and social-media accounts are sold, resold and repackaged there by specialized data brokers.
The central role of the "infostealer"
The most common way these markets get supplied isn't a spectacular hack targeting a single person: it's malware called an infostealer, installed without the victim noticing (often via a booby-trapped file or fake software), which harvests saved usernames and passwords from the browser in bulk. The result is then resold as "logs" — batches of raw data, by the hundreds or thousands, before even being sorted.
Source: Europol, IOCTA 2025.Authorities are pushing back
Taking these markets down isn't just a theoretical threat to their operators. Joint operations between several countries have already demonstrated authorities' ability to disrupt them:
Vocabulary worth knowing
Infostealer
Malware designed to harvest saved usernames, passwords and session cookies from an infected device in bulk.
Log
A raw batch of data stolen by an infostealer, sold as-is before sorting — often hundreds of credentials at once.
Access broker
A specialized reseller who buys stolen access or data in bulk to resell it, sorted and packaged, to other criminals.
Closed market
A platform accessible only by invitation or after vetting, to limit the risk of infiltration by authorities or security researchers.
Frequently asked questions
What exactly is the dark web?
A part of the internet not indexed by standard search engines, requiring specific software to access, originally designed for anonymity. A minority of its use is criminal, but that's the part relevant to stolen-data resale.
How do my credentials end up on the dark web?
Most often through malware called an infostealer, installed on a device, which harvests saved usernames and passwords in bulk and then resells them as grouped "logs" on specialized markets.
How can I know if my data is there?
Have I Been Pwned (haveibeenpwned.com) lets you check for free whether your email appears in an already-catalogued data breach, without needing to access the dark web yourself.
Other markets we cover
This report leans on Europol data, but the trade in stolen data isn't confined to one region. Here's what's documented in four other major English-speaking markets.
🇦🇺Australia — 9,587 credential-exposure alerts in eight months
The Australian Signals Directorate's cyber centre sent 9,587 credential exposure notifications to roughly 220 organisations in under eight months of the 2024-25 financial year, as usernames and passwords harvested by infostealer malware kept surfacing for resale on dark web forums.
ACSC, Annual Cyber Threat Report 2024-25.🇬🇧United Kingdom — millions of records from one retailer breach
The April 2025 ransomware attack on Marks & Spencer, linked to the DragonForce group, exposed names, addresses, phone numbers, dates of birth and order histories for millions of customers — the kind of profile data that typically ends up traded on dark web markets, even when passwords themselves weren't taken.
TechCrunch, May 13, 2025 · Marks & Spencer corporate cyber update.🇨🇦Canada — Social Insurance Numbers of 140,000 customers
A March 2025 ransomware attack on Nova Scotia Power exposed the personal and financial information of nearly 280,000 customers, including Social Insurance Numbers for about 140,000 of them, with stolen data published online before the breach was detected. Some affected customers have since been alerted that their data is circulating on the dark web.
Nova Scotia Power breach disclosure, March 2025.🇮🇳India — among the countries hit by a 16-billion-credential leak
India's national computer emergency response team, CERT-In, issued a public advisory on June 23, 2025, after security researchers compiled roughly 16 billion stolen login credentials — pulled together from infostealer malware and misconfigured databases — into one of the largest credential leaks on record, urging citizens to change their passwords.
CERT-In advisory, June 23, 2025 · reported by Medianama.Go further
Egidio — The Threat Laboratory, "Dark web: where your stolen data goes, explained simply", egidio.app/en/laboratoire/dark-web/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.