What to Do If Your Information Is on the Dark Web

Techwalla may earn compensation through affiliate links in this story. Learn more about our affiliate and product review process here.

What to Do If Your Information Is on the Dark Web

Getting a dark-web alert is unsettling, but it's not a verdict. Knowing what to do if your information is on the dark web starts with understanding what the alert actually means: it can mean that data tied to your name, email, or Social Security number showed up somewhere a monitoring service watches, not that fraud has already happened.

The Federal Trade Commission is explicit that credit freezes don't require proof of anything first. "Anyone can do it, any time," the agency says, meaning nobody needs to wait for a breach notice or a fraudulent charge before acting (FTC). That single fact reframes the whole problem: the strongest protections are available on suspicion alone, and waiting for certainty just burns the head start.

Identity-monitoring services, for their part, may flag when personal data shows up on sites "identity thieves use to trade stolen information" (FTC), but they have real blind spots worth understanding before leaning on one too heavily. What follows is the order that matters: freeze credit first, layer on account security and monitoring next, and escalate to formal reporting only once there's an actual reason to suspect misuse.

Advertisement

What to do if your information is on the dark web: start with these steps

Video of the Day

Diagram showing how to place a credit freeze separately with Equifax, Experian, and TransUnion—what to do if your information is on the dark web

A credit freeze is the single most effective step available, and it costs nothing. It blocks new credit accounts from being opened in your name, including by you, until the freeze is lifted (FTC).

To freeze all three credit reports, contact Equifax, Experian, and TransUnion. There's no single request that covers all three at once, so each one has to be placed separately (FTC).

Placing and lifting a freeze is free, doesn't touch a credit score, and has no expiration date to track. It stays active until the consumer removes it (FTC).

There's one practical wrinkle. While frozen, nobody can open new credit, including the account holder applying for a car loan or an apartment. The fix is simple: ask the lender which bureau it plans to check, then contact only that bureau to lift the freeze temporarily, and put it back once the application is done (FTC).

Parents can also freeze a credit file for a child under 16. The process differs from an adult freeze, and each bureau publishes its own instructions for minors (FTC), which is worth doing if a family data breach exposed a child's Social Security number.

One limit is worth flagging now. A freeze is built to block new credit accounts; it won't alert anyone to a bank withdrawal, tax-refund fraud, or several forms of benefits fraud (FTC). That gap is exactly why the rest of this guide exists.

Advertisement

Video of the Day

Credit freeze vs. fraud alert for identity theft protection

A freeze and a fraud alert solve different problems, and knowing the difference determines which one, or both, makes sense.

A freeze blocks new credit outright. Nobody can open an account while it's active. A fraud alert takes a lighter approach: it doesn't stop businesses from viewing a credit report, but it does require them to verify identity before approving new credit (FTC).

Fraud alerts are also faster to set up. Contacting one bureau is enough, since that bureau is required to notify the other two (FTC); a freeze, by contrast, requires contacting all three separately.

An initial fraud alert lasts one year and can be renewed. An extended fraud alert lasts seven years, but it's reserved for people who have experienced identity theft and completed an FTC identity theft report or filed a police report (FTC). It's not simply a stronger option available to anyone who wants extra caution.

Active-duty servicemembers have a fourth option: a one-year alert renewable for the length of a deployment, plus removal from credit and insurance marketing lists for two years (FTC). Active-duty personnel and National Guard members can also sign up for free electronic credit monitoring by contacting each of the three bureaus (FTC).

None of this is either/or. Having a freeze in place doesn't rule out also placing an initial fraud alert (FTC), and using both means a would-be creditor faces two separate hurdles instead of one. Both are free, so there's little reason to pick only one.

Advertisement

Advertisement

Secure the accounts a credit freeze can't touch

Illustration of a user rotating exposed passwords and turning on phishing-resistant multi-factor authentication for critical accounts after a credential-compromising npm supply-chain incident

If what leaked is a password or login credential rather than a Social Security number, none of the above matters much. That kind of exposure isn't about new credit accounts opening; it's about someone logging into an account that already exists.

A September 2025 CISA alert on a supply-chain attack against npm, the world's largest JavaScript registry, shows how that plays out at scale. Malware scanned compromised developer environments for credentials and pulled GitHub access tokens and cloud API keys across more than 500 affected packages before spreading further through the registry (CISA, Sept. 2025). It's a developer-focused incident, and CISA's response guidance was written for developers: rotate credentials immediately and require phishing-resistant multifactor authentication on critical accounts like GitHub and npm (CISA, 2025).

The consumer version of that advice is simpler. Start with whatever service was actually breached and change that password first. Move to email next, since it's usually the account that resets everything else. Then check banking and payment apps, along with any other login that reuses a password already known to be compromised.

CISA's broader ransomware guidance, written for organizations rather than individual consumers, recommends unique passwords of at least 15 characters and phishing-resistant multifactor authentication for email, VPNs, and systems tied to critical access (CISA, 2023). It's a reasonable standard to borrow for personal accounts, particularly email and banking, even though the agency wrote it with organizational networks in mind rather than a household inbox.

Advertisement

Advertisement

What to do if your Social Security number is exposed: monitoring and its limits

Side-by-side illustration showing identity monitoring alerts (credit-bureau activity, address changes, new service applications) versus gaps like fraudulent tax returns and benefits claims

A Social Security number exposure raises a different question than a stolen password: what's actually watching for misuse, and what does it miss?

Paid identity-protection services come in a few forms, and they're often bundled through a bank, credit card issuer, or employer benefits program rather than bought outright (FTC). Credit monitoring tracks one, two, or all three credit bureaus and flags suspicious activity on a report, usually for a monthly or annual fee (FTC). Identity monitoring casts a wider net: it may alert someone when their information shows up in a change-of-address request, an application for new utility or wireless service, a payday loan application, social media, or sites identity thieves use to trade stolen data (FTC).

Both have the same structural gap. Most identity-monitoring services won't catch someone using a stolen Social Security number to file a fraudulent tax return, claim Social Security or unemployment benefits, or access Medicare or Medicaid (FTC). Credit monitoring won't flag a bank withdrawal or a hijacked tax refund either, since neither shows up on a credit report (FTC).

Identity recovery services and identity theft insurance round out the paid options, and both are narrower than their names suggest. Recovery services typically provide a counselor or case manager to help sort out the aftermath, sometimes bundled with monitoring and sometimes billed separately (FTC). Identity theft insurance generally doesn't reimburse stolen money or the financial loss itself, and most policies won't pay out if the loss is already covered by homeowner's or renter's insurance (FTC). It's worth checking the deductible and coverage terms closely before assuming a policy is a safety net.

CISA's ransomware guidance tells organizations they should consider subscribing to services that monitor the dark web for compromised credentials (CISA, 2023). That's sound advice, but a monitoring alert is a detection tool, not a shield. It tells someone that something showed up somewhere; it doesn't replace the freeze and password-reset steps covered above.

One low-cost habit closes part of the gap on its own: pulling free credit reports regularly and scanning for accounts that don't look familiar. The FTC lists an unrecognized account as a possible sign of identity theft (FTC), and checking costs nothing.

Advertisement

Advertisement

If you suspect fraud: report and recover

Screen mockup of IdentityTheft.gov where a user files an identity theft report and receives a step-by-step recovery plan with pre-filled letters for creditors and credit bureaus

The freeze, the fraud alert, and the account security steps above are worth doing on suspicion alone, well before anyone confirms what a dark-web listing actually contains. Formal reporting sits on a different tier, though the bar for it is lower than it might seem: the FTC's guidance is to report if someone thinks their identity was stolen, not to wait for airtight proof (FTC). Finding an unfamiliar account on a credit report, or otherwise suspecting misuse, is reason enough to act.

IdentityTheft.gov is where that report goes. The site generates a free, personalized recovery plan covering more than 30 types of identity theft, from credit fraud to benefits fraud, and it tracks progress as steps are completed (FTC). It also produces pre-filled letters and forms to send to credit bureaus, businesses, and debt collectors, which cuts out a lot of the guesswork in disputing fraudulent activity (FTC).

Reports can be filed in English at IdentityTheft.gov or in Spanish at RobodeIdentidad.gov. For other languages, calling 877-438-4338 and pressing 3 connects to interpreter support, available from 9 a.m. to 5 p.m. Eastern (FTC).

Filing that report matters beyond the recovery plan itself. A completed FTC identity theft report, or a police report, is the documentation needed to qualify for the seven-year extended fraud alert described earlier (FTC), the step up from the one-year initial alert that anyone can place without it.

Advertisement

Advertisement

What to revisit if a new alert shows up

The sequence holds regardless of what triggers it: freeze credit with all three bureaus, secure the accounts a freeze can't touch, add monitoring to catch what neither one sees, and save IdentityTheft.gov for the moment there's an actual reason to suspect misuse. None of the earlier steps require waiting for that moment to arrive.

If another alert lands later, or a credit report turns up an account that doesn't belong, the response doesn't start over from scratch. A freeze already in place stays in place. What changes is the last step, the point where a formal report, and the recovery plan attached to it, finally earns its place.

Advertisement

Advertisement