Flamingo Raises $4.5M Seed Round

Skip to content

A client forwards an email from a rival IT provider: a scan of their domain turned up 14 results on the dark web, and would they like to talk. The results date from 2012, 2016 and 2020, and none of them touch an account that still exists. That is the problem with reading a dark web scan cold, so this post covers what a scan indexes, which rows matter, and what to do in the first hour when one of them does.

TL;DR

  • A dark web scan matches your email addresses or domain against indexed breach dumps, paste sites and stealer logs. It cannot see data that was sold privately and never indexed.
  • Old breach rows with hashed passwords are noise. Stealer log rows are the signal, because they come from an infected device and name the sites the password worked on.
  • A one-off scan is a snapshot. Monitoring is the same search run every time new data lands, and you already own one layer of it if you run Microsoft Entra.
  • When a current company credential shows up: reset with MFA, revoke sessions, read the sign-in log, then find the device. Skipping the device is how the same account shows up again next month.
  • Start free: HIBP domain search and Pwned Passwords, plus the banned-password and leaked-credential checks built into Entra. Pay for monitoring when you need per-client reporting or breadth beyond those feeds.

What a Dark Web Scan Looks At

A dark web scan takes an identifier you give it, an email address or a whole domain, and matches it against data someone has already collected from criminal sources. The scan does not crawl the dark web live. It searches an index.

That index has four kinds of rows in it:

SourceWhat a row looks likeHow much it matters
Breach dumpsAn email address, often with a hashed password, from a site that got breached (LinkedIn 2012, Dropbox 2016)Low if the hash is strong and the password changed since; high if it was reused
Paste sitesText dumped on Pastebin-style sites, sometimes credentials, often transientMedium; check it fast, it may be gone tomorrow
Stealer logsEmail, password and the website it was typed into, lifted by malware from an infected machineHigh; this is a live credential from a device you may still own
Forums and marketplacesListings of access for sale, usually a company name and a price, rarely the credential itselfHigh when your domain is named; you are being shopped

Have I Been Pwned's definition of the third kind is the one to keep in mind. Stealer logs "are the result of malicious software running on infected machines that collect email addresses, passwords and the website they're entered into at login." A breach dump tells you a site you used got hit. A stealer log tells you a device got hit.

Two things no scan can show you. Data sold one-to-one and never posted anywhere stays invisible, and so does a session token stolen last week that lets someone into a mailbox without a password at all. A clean scan means nothing indexed matched, not that nothing is out there.

The consumer products on page one of Google (Experian, Aura, the identity-monitoring side of Microsoft Defender) scan one person's identity: email, phone, Social Security number, card numbers. A business scan works on a verified domain and returns every address under it, and the useful ones add the stealer log view of which sites a corporate address was used on. If you run the consumer version for a company, you will be checking one inbox at a time.

Reading the Report Without Panicking

A typical domain report for a 40-person company lists a few dozen rows. Sort them by three questions before anyone resets anything.

Does the account still exist? Breach rows carry whatever address the person signed up with, and a decade-old dump is full of staff who left years ago. Check the row against your directory and your client offboarding checklist before it becomes a ticket.

Is the password shown, hashed, or absent? HIBP never loads passwords next to addresses at all; "no password is stored next to any personally identifiable data." Commercial services often show a hashed value or a partial plaintext. A hash from 2016 is a reason to confirm the password changed since. A plaintext password from this year is a reason to act now.

Where did the row come from and when? A 2012 breach dump with a salted hash is housekeeping. A 2026 stealer log naming your mail server and your accounting app is an incident.

The r/msp thread below is a good reminder of how these reports get used. A franchise MSP cold-contacted a client with a domain report as a sales hook, and the incumbent answered with their own report showing two old dumps since 2019. The replies land on one point: SSO, a password manager and MFA make bulk credential dumps close to worthless, and the live threat, stolen session tokens, never shows up in a scan at all.

Reports also misattribute. Another r/msp admin got ten "password exposed" notices for a marketing account, all hashed the same way and all dated 2020, linked to a Dutch museum page and two wedding blogs the account had never touched. The likely story is a WordPress plugin breach that swept up addresses from many sites and got filed under each of them. Treat a cluster of same-date, same-hash rows as one event, and treat the vendor's "reset the password" as the floor, not the answer.

Why Stealer Logs Are the Rows That Matter

Infostealers are malware that sit on a machine and record every login: the site, the address, the password. The logs get sold in bulk, and that is what has changed the scan business over the last two years.

In January 2025, HIBP loaded a corpus of 220 million unique email-and-domain pairs from stealer logs, covering 69 million addresses, and started returning the websites each address was captured on to verified domain owners. Troy Hunt ran a Fortune 500 domain through it and found thousands of corporate addresses paired with services from PayPal to gaming sites, each with the password that was typed into it. The old question was "which site leaked my users?" The new one is "which of my users' machines is infected, and what did it watch them type?"

Verizon's 2025 Data Breach Investigations Report put a number on the device side. Of the systems compromised by an infostealer that held possible corporate login data, 46% were non-managed devices: personal laptops, or company laptops used outside policy. The same report found that 54% of victims posted to ransomware extortion sites had their domain show up in at least one stealer log or marketplace listing before the attack. The credential did not leak from your server. It leaked from a browser on a machine you may not control.

That reframes a scan result. A stealer row for jsmith@yourdomain against mail.yourdomain.com and app.yourpayroll.com means an endpoint recorded those logins. Resetting the password closes one door, but the malware is still watching the next one get typed. The fix has to reach the device, which is why a BYOD policy template that says which machines may hold corporate logins is part of dark web response, not a separate project.

One-Off Scan or Monitoring?

A scan answers "what is indexed about us today." Monitoring answers "tell me when that changes." Both search the same indexes; the difference is who is paying attention on a Tuesday in March when a new log batch lands.

The timing is the whole argument. Credentials are usually traded before they appear in any public index, so by the time a one-off scan sees them, the window in which they were worth something may have closed, or the attacker may already be inside. Monitoring does not fix the delay, but it fires the day the row appears instead of whenever someone next remembers to run the report.

For a business, monitoring takes three forms, and you may already be running one:

HIBP's domain search sends a notification when a new breach or stealer log contains an address on a domain you have verified. It is free for small domains and sold by size above that, and it is the cheapest reliable signal there is.

Microsoft Entra ID Protection has a detection called leaked credentials. Microsoft runs its own scanning pipeline across dark web forums, breach dumps, paste sites and law enforcement seizures, then validates what it finds against your tenant's current password hashes. A detection only fires on a confirmed match, and a cloud password reset clears it. If you license Entra ID P2, this is already on, and it checks the one thing a third-party scan cannot: whether the leaked password is the password right now.

Commercial monitoring services (SpyCloud, Dark Web ID and the like, often resold through an MSP) add breadth: more sources, forum chatter, per-client reports, and alerts that go to the MSP's queue rather than to one admin's inbox. That breadth is what you pay for; the data under it overlaps heavily with the free feeds.

For a plain-language primer on how the dark web and these monitoring services fit together, IBM's explainer is a good one to send to a client who has just received a scary report:

What to Do in the First Hour

A current credential for a live account has appeared. The order below is the one that holds up, and it matters because step five is the one that gets skipped.

StepActionWhy in this order
1. ConfirmMatch the row to a real account, check the source date, decide if the password could still be currentHalf the rows in any report fail this step; don't reset the whole company
2. Reset with MFAForce a password change that requires MFA first, not a helpdesk reset over the phoneNIST SP 800-63B Rev. 4 (August 2025): verifiers "SHALL force a change if there is evidence that the authenticator has been compromised"
3. RevokeRevoke refresh tokens and active sessions, re-register MFA if the stealer log is recentA reset does not sign out a session that is already open
4. Read the logSign-ins from new countries or devices, new inbox rules, new OAuth app consents, mail forwardingThis tells you whether the credential was used, which decides whether this is an alert or an incident
5. Find the deviceFor a stealer row, identify which machine typed that login and isolate it; scan it; reimage if in doubtThe malware is still running; a reset without this is a reset you will repeat
6. Block the passwordAdd the exposed value and its variants to your banned password listEntra Password Protection's custom banned list stops the same base term coming back as Summer2026!

Step four is where this joins your incident response plan. If the sign-in log shows the credential was used, the scan result was the first sighting of a breach, not a warning about one, and the notification clocks in that plan start now.

Step five is the one that needs tooling rather than a console. Stealer logs name the site and the address but not the hostname, so you work backward: whose account, which machines that person signs into, which of those has a browser profile with that site saved. On a managed fleet that is a script run across the client's devices with the output collected, which is one of the things OpenFrame does; on an unmanaged personal laptop it is a phone call and a difficult conversation about the BYOD policy.

What to Use, Free First

The r/cybersecurity thread below is the question every IT lead eventually asks: an external audit said staff credentials were on the dark web, the org already has MFA and sign-in monitoring, and the sting was being told by someone else. The replies split between free feeds and paid services, and that split is the right way to shop.

Start with the layer you already own. Entra's global banned password list is applied to every tenant and cannot be switched off; the custom list is where you add your company name and product names. Pwned Passwords is free and checks a password against breach corpora without sending it anywhere: the client sends the first five characters of the SHA-1 hash and compares the rest locally. NIST now says verifiers "SHALL compare the prospective secret against a blocklist that contains known commonly used, expected, or compromised passwords," and that same revision says to stop forcing periodic changes. Screen at set-time, rotate on evidence. If your fleet still runs the most common passwords, this is the fix.

Then verify your domains in HIBP and turn on notifications. It covers breach dumps and the stealer log view, for every address on the domain, and the dashboard is the same one a paid service would be reading from in part.

Pay for a monitoring service when one of these is true: you manage several client tenants and need per-client reports and alert routing; you need forum and marketplace coverage, which the free feeds do not index; or a client's insurer or framework asks for "dark web monitoring" by name, in which case check the cyber insurance requirements wording before buying the most expensive reading of it. Evaluate on three things: whether the service shows the website a stealer log came from, how quickly a new log batch reaches your alert, and whether the alert carries enough to act on without a support ticket.

What a scan will not replace is the control that makes the finding harmless. A password manager that generates unique passwords per site means a stealer row for app.yourpayroll.com does not also open the mailbox; our password manager roundup covers the multi-tenant options. Phishing-resistant MFA means a captured password on its own does not sign anyone in. Those two make the report shorter every quarter.

The Short Version

A dark web scan is a search of indexed stolen data, not a live look at criminal markets, and a clean result is a clean index, not a clean company. Read reports by account, password form and date; old hashed rows are housekeeping and recent stealer rows are incidents. When a current credential shows, reset with MFA, revoke sessions, read the sign-in log, and then find the machine, because the malware that typed the password into a log is still typing. Verify your domain in HIBP, switch on the Entra detections you already pay for, and buy monitoring for breadth and reporting rather than for the data itself.

Next: how IAM tools turn a leaked password into a non-event, and the attack surface map that shows where those credentials get used.

FAQ

What is a dark web scan?

A dark web scan searches an index of data collected from breach dumps, paste sites, stealer logs and criminal marketplaces for an email address or a domain you specify. It reports which indexed sources contain that identifier and, depending on the service, whether a password was exposed and in what form. It does not search the dark web live, and it cannot see data that was never indexed.

Can a dark web scan find stolen passwords?

Sometimes. Breach dumps often hold hashed passwords, and some services show a hash or a partial plaintext so you can tell whether the value is current. Stealer logs hold the plaintext password a victim typed. Have I Been Pwned deliberately never stores or shows passwords next to email addresses, and instead offers Pwned Passwords, where you check a password hash against breach corpora without revealing the password.

What is the difference between a dark web scan and dark web monitoring?

A scan is a one-time search of the index as it stands today. Monitoring runs the same search every time new data is added and alerts you on a match. For a business, HIBP domain notifications and Microsoft Entra ID Protection's leaked credentials detection are monitoring; a paid service adds more sources and per-client reporting on top.

What should I do if my company email shows up on the dark web?

Confirm the account still exists and the password could still be current. If it could, force a password change that requires MFA, revoke sessions and refresh tokens, and read the sign-in and mailbox-rule logs to see whether the credential was used. If the row came from a stealer log, find and isolate the device that recorded it before anything else, then add the exposed password to your banned list.

Is a free dark web scan safe to use?

Have I Been Pwned's search and domain verification are safe and widely used, and Pwned Passwords never sends your password off the device. Be careful with free scans that require contact details or a phone number to see results: some are lead-generation forms for a sales call, and a few vendors have used the resulting report as a cold-outreach hook. Check what a service does with the address you give it before you give it.

Conrad Lunderstedt

Conrad Lunderstedt

Solution Architect

I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

blog

A dark web scan searches an index of data collected from breach dumps, paste sites, stealer logs and criminal marketplaces for an email address or a domain you specify. It reports which indexed sources contain that identifier and, depending on the service, whether a password was exposed and in what form. It does not search the dark web live, and it cannot see data that was never indexed.
Sometimes. Breach dumps often hold hashed passwords, and some services show a hash or a partial plaintext so you can tell whether the value is current. Stealer logs hold the plaintext password a victim typed. Have I Been Pwned deliberately never stores or shows passwords next to email addresses, and instead offers Pwned Passwords, where you check a password hash against breach corpora without revealing the password.
A scan is a one-time search of the index as it stands today. Monitoring runs the same search every time new data is added and alerts you on a match. For a business, HIBP domain notifications and Microsoft Entra ID Protection's leaked credentials detection are monitoring; a paid service adds more sources and per-client reporting on top.
Confirm the account still exists and the password could still be current. If it could, force a password change that requires MFA, revoke sessions and refresh tokens, and read the sign-in and mailbox-rule logs to see whether the credential was used. If the row came from a stealer log, find and isolate the device that recorded it before anything else, then add the exposed password to your banned list.
Have I Been Pwned's search and domain verification are safe and widely used, and Pwned Passwords never sends your password off the device. Be careful with free scans that require contact details or a phone number to see results: some are lead-generation forms for a sales call, and a few vendors have used the resulting report as a cold-outreach hook. Check what a service does with the address you give it before you give it.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.