Dark web monitoring

Your credentials are already out there. The question is whether you know it.

CAVRIX continuously checks your domains, mailboxes and accounts against breach databases, combolists and infostealer logs. When there is a hit, you do not get an alert, you get the finding already handled.

A breach at someone else's service is not someone else's problem. If your people reused that address and password on a company account, the breach is yours.

The numbers

Why this concerns you

87%

of German companies were hit by theft, espionage or sabotage in the past year.

35%

of the data leaks known to the German BSI also contained passwords.

80%

of the attacks reported to the German BSI targeted small and mid-sized companies.

48%

of all breaches worldwide involve a third party, not your own network.

Sources: Bitkom Wirtschaftsschutz 2025 (1,002 companies with 10+ employees surveyed), BSI situation report 2025 (461 disclosed data leaks), Verizon Data Breach Investigations Report 2026. Industry data, not a guarantee for any individual case.

The threat

The attack does not start with you. It starts at a provider you have never heard of.

Password reuse01

Someone else's leak becomes your login.

A provider's database spills and millions of addresses go into circulation. Anyone who used the same combination on a company account has already unlocked the door. Automated login attempts work through that in minutes, across every known service.

Infostealers02

A private device, a company login, a sale.

Malware on a personal machine harvests stored credentials, session cookies and browser profiles. What it finds is traded as a ready-made package, including live sessions that walk straight past multi-factor authentication. A company login from a home office is worth exactly as much as one from the office.

Supply chain03

Your supplier becomes the way in.

Almost half of all breaches involve a third party. Access to shared portals, joint project spaces and contractor accounts circulates just like your own. Under NIS2 the supply chain stays your responsibility regardless.

The solution

Find it. Judge it. Close it.

An alert without an action is just another open item on your list. CAVRIX works the finding instead of forwarding it to you.

We monitor what belongs to you.

  • All company domains including subdomains
  • Employee mailboxes and shared role addresses
  • Management and other exposed roles
  • Contractor and supplier accounts
  • Brand and domain abuse

We judge every finding.

  • Is the hit real, current and usable?
  • Which systems hang off this account?
  • Was the password reused elsewhere?
  • Have there already been login attempts with it?
  • A clear priority instead of a hit list

We close the gap.

  • Password reset, sessions terminated
  • Multi-factor authentication enforced
  • Account watched, anomalies tracked
  • Affected people informed and advised
  • Finding and action documented with a date
How it works

From first analysis to continuous monitoring. In days, not months.

Day 0

Take stock

We map your domains, mailboxes and exposed roles and run the first match against the known breach corpus.

48 hours

First assessment

You get a clear report: which accounts are affected, how old the findings are, and which of them are still dangerous today.

Week 1

Clean up

Affected accounts are reset, sessions terminated, multi-factor authentication rolled out and password reuse eliminated.

Ongoing

Monitor

New findings reach us around the clock. Critical hits are handled immediately and you are told what is already done.

Compliance

What regulators and auditors actually ask for.

Others claim across the board that dark web monitoring is mandatory. We show you the passages verbatim and say openly where no explicit obligation exists.

NIS2, Art. 21(2)

Incident handling, supply chain, MFA

The directive requires incident handling under point (b), supply chain security under point (d) and multi-factor authentication under point (j). Transposed in Germany as section 30 BSIG. Leaked credentials are an externally verifiable risk and show where those measures hold or fail.

GDPR, Art. 32 and 33

Prove effectiveness, meet the deadline

Art. 32(1)(d) requires a process for regularly testing and evaluating the effectiveness of technical measures. Art. 33(1) sets the 72 hour notification clock running from awareness. Without monitoring you become aware later, while the damage still happened earlier.

ISO 27001:2022, A.5.7

Threat intelligence

The control added in the 2022 revision requires threat information to be collected, analysed and fed into risk assessment. Monitoring leaked credentials is a standard implementation. A.5.17 on authentication information applies alongside it.

BSI IT-Grundschutz, DER.1.A12

Evaluating information from external sources

The requirement names the method almost verbatim: to gain new insight into security-relevant events, external sources should be consulted, assessed and, where relevant, escalated into incident handling. ORP.4 on access management and DER.2.1 on incident handling apply alongside it.

Neither NIS2 nor the GDPR names dark web monitoring explicitly. So we do not claim an obligation, we show which requirements it measurably supports. The method is named explicitly in ISO 27001 A.5.7 and in BSI DER.1.A12. This overview is a technical assessment, not legal advice.

Free

Start with the password. It takes 10 seconds.

Check without signing up whether a password appears in known breaches, and see which breaches went public most recently. The check runs in your browser, the password never leaves your device.

What you gain
24/7

monitoring of your domains, mailboxes and exposed roles.

< 15 min

response on critical findings, proactively in your channels.

0

effort for you, we work the finding and document it.

FAQ

Questions about dark web monitoring

  • Do you really crawl the dark web live?

    No, and nobody serious claims to. Monitoring runs against continuously updated corpora of breach databases, combolists, paste sites, infostealer logs and the relevant channels. Live crawling of the entire dark web does not exist, neither here nor at any competitor.

  • Is a one-off scan not enough?

    A scan is a snapshot. Today's finding comes from a breach that happened long ago, and the next one lands next week. This only works as a continuous process with a clear response attached.

  • What happens when you find something?

    We verify whether the hit is real and usable, reset affected accounts, terminate open sessions, enforce multi-factor authentication and inform the people concerned. The case then sits dated in your evidence record.

  • Do we get to see plaintext passwords?

    No. We work with proof of exposure and reset. Passing on third-party plaintext credentials would be neither necessary nor lawful.

  • Is dark web monitoring mandatory under NIS2?

    Not by name. NIS2 requires risk analysis, incident handling and effective access security. Monitoring is one of the few measures that produces externally verifiable evidence for all three. That is exactly how we argue it in an audit.

  • But we already have multi-factor authentication.

    Correct and important, but not sufficient. According to Sophos State of Ransomware 2026 (2,158 decision makers surveyed at companies with 100 to 5,000 employees), multi-factor authentication was in place in some form in 97 percent of cases involving compromised credentials. Stolen live sessions walk straight past it, which is why terminating open sessions is always part of the response.

  • What about our employees' private devices?

    That is where most findings originate. We monitor the company identity regardless of which device compromised it, and derive the measures for your systems from that.

  • How does this sit with data protection law?

    We monitor company identities on the basis of a legitimate interest in the security of processing, with a data processing agreement and documented measures. Processing happens in the EU and plaintext passwords are not stored.

How much of your company is already in circulation?

Free exposure analysis, clear result, no commitment.