Dark web monitoring
Find out your passwords leaked before someone uses them.
Staff reuse passwords. The websites they sign up to get breached. Their work login then ends up for sale, and most businesses only find out when someone logs in as them.
We watch for your business in those leaks all the time. When something turns up, an engineer checks it and fixes it with you.
What we watch for
Four kinds of leak that lead to a break-in.
Staff passwords from other sites
When a website your staff signed up to is breached, we find their work email and password in the leak. Reused passwords are the most common way in.
Infected devices
Malware that quietly steals saved passwords and sign-in sessions from a laptop. We spot your accounts in those stolen logs.
Fake versions of your business
Lookalike web addresses registered to trick your clients into paying the wrong account or logging in to a fake page.
Your own data, leaked
Client lists, documents or financial records posted on forums or sale sites. Often the first sign of a breach nobody noticed.
What happens
When something turns up, we own it until it is fixed.
- 01
We set up the watch list
Your web addresses, staff email addresses and business name. It takes one short call.
- 02
Scanning runs all the time
Leak sites, criminal forums and stolen-password logs are checked around the clock.
- 03
We check every hit
An engineer confirms each match is real before you hear about it, so you are not chasing false alarms.
- 04
We fix it with you
Passwords reset, sessions signed out, old accounts closed. If client data is involved, we help you work out whether you must notify the OAIC.
Why it matters
Breaches in Australia are not slowing down.
1,113
data breaches were reported to the Australian privacy regulator in 2024, the highest yearly total since mandatory reporting began in 2018.
Source: OAIC Notifiable Data Breaches Report, July to December 2024.
The questions we get asked the most.
- What is the dark web?
- Parts of the internet you cannot reach with a normal browser or search engine. Criminals use hidden forums and marketplaces there to buy and sell stolen passwords and business data.
- Can you remove our data from the dark web?
- Usually not. Stolen data is copied and shared quickly. What we can do is make it useless: change the exposed passwords, sign out stolen sessions and close accounts before an attacker uses them.
- What happens when you find something?
- An engineer confirms it, tells you what was exposed and where, and takes care of the fix with you. For exposed passwords that means a reset and a check for reuse. For leaked client data, we help you assess it under the Privacy Act.
- Is dark web monitoring required?
- No law or the ASD Essential Eight requires it by name. It does help you meet the Privacy Act requirement to take reasonable steps to protect personal information, and to spot breaches you would otherwise miss.
- Do you work outside Brisbane?
- Yes. Monitoring is done remotely, so businesses anywhere in Australia get the same scanning, alerts and engineers helping with the fix.
Want to know what is already out there?
Give us your business web address and we will tell you what we can find and what to do about it.

Remote Support