Dark Web Leak: What to Do If Your Data Is Exposed
Read Time 12 mins | 09 Mar 2026 | Written by: Hastin Lia
A dark web leak means your credentials or personal records have ended up in a stolen-data dump that criminals can search, trade, and resell. You cannot erase that data once it is out. You can make it useless: confirm what leaked, change every password that reuses the exposed one, turn on multi-factor authentication, and report the incident if a company is involved.
Finding your email address in a leak is usually the start of an incident. Attackers work through fresh dumps within days of publication, testing the credentials against banks, mailboxes, and corporate logins.
This guide covers what a dark web leak actually is, how to check whether you are in one, what to do in the first 24 hours and the first week, and which mistakes make the damage worse. If you are in Malaysia, it also covers the PDPA reporting clock that starts the moment a company discovers the breach.
What a Dark Web Leak Actually Is
The dark web is the portion of the internet that standard search engines do not index and that normally requires Tor or similar software to reach. Criminals use it because it separates a marketplace from the identity of the people running it.
"Dark web leak" gets used loosely for three different things, and the difference decides what you should do next.
Ransomware leak sites
When a ransomware group breaks into an organisation, it copies data before encrypting anything. If the victim refuses to pay, the group publishes the stolen files on a leak site it operates itself. These are pressure tools aimed at one named company, and the exposure is usually documents, HR files, contracts, and customer records rather than passwords.
Combolists and breach dumps
These are aggregated files of email addresses and passwords assembled from many separate breaches. A single combolist can be enormous, and most of its rows are years old and recycled from earlier dumps. This is the category most people land in, and it is why the same address keeps reappearing in new "breaches" it was never directly part of.
Infostealer logs
Infostealer malware sits on an infected laptop or phone and harvests saved browser passwords, session cookies, and autofill data. The output gets sold as a "log". This category is the most dangerous of the three, because the data is fresh, it includes session tokens that can bypass a password change entirely, and its presence means a device is still infected. Changing your password does nothing if the malware is still running.
Our breakdown of how dark web marketplaces buy and resell stolen data explains how a single leaked record travels between these three formats.
How to Check If You Are in a Dark Web Leak
You cannot browse the dark web yourself to look, and you should not try. The practical route is a service that has already indexed known breach corpora and lets you search it.
Checking a personal email address
Have I Been Pwned is the long-running free reference for individuals. Enter an address and it returns the named breaches that address appears in, plus what data classes were exposed in each one. Treat the result as a floor. It covers only the breaches that have been publicly identified and loaded into the index, so a clean result tells you the address has not surfaced in those corpora yet, which is a weaker statement than being safe.
Two habits make these checks far more useful. Check every address you own, including old ones you no longer read, because those are often tied to accounts you forgot to close. Read the exposed data classes as carefully as the list of breach names. A leaked password matters far more than a leaked newsletter subscription.
Checking a company domain
Individual lookups do not scale past a handful of people. An organisation needs domain-level monitoring that watches every mailbox on the domain continuously and alerts on new appearances, because the gap between a leak appearing and someone noticing is where the attack happens. IBM put the global average cost of a breach at a record USD 4.99 million in its 2026 Cost of a Data Breach Report, a 12% rise in a single year, and slow detection is a consistent driver of that figure.
SiberMate's breach monitoring watches company domains and dark web sources for exactly this, then notifies the affected employees and their managers when it finds an exposure, so the alert reaches the people who can act on it.
What to Do in the First 24 Hours
Work in this order. The sequence matters more than the speed.
Step 1: Confirm what actually leaked
Identify which data classes the exposure contains. Knowing that something leaked tells you nothing actionable on its own. A password needs changing immediately. An identity card or passport number cannot be changed at all, so it needs monitoring for fraudulent applications made in your name instead. Session cookies call for a different move again: terminate every active session. Write down which accounts are affected before you touch anything, because you will lose track otherwise.
Step 2: Change the reused passwords first
Start with the accounts that share the exposed password rather than with the breached account itself. Attackers automate this: they take one leaked pair and try it across hundreds of services, which works far more often than it should. Verizon's 2025 Data Breach Investigations Report research found that compromised credentials were an initial access vector in 22% of the breaches it reviewed, and that for the median user only 49% of passwords across different services were distinct from one another. Roughly half of a typical person's logins are duplicates waiting to fall together.
Prioritise the email account attached to everything else, then banking, then anything holding payment details. A password manager solves the reuse problem permanently and removes the temptation to invent a memorable variation of the password that just leaked.
Step 3: Turn on multi-factor authentication
Multi-factor authentication is what stops a leaked password from becoming a compromised account. Enable it everywhere it is offered, starting with email. Prefer an authenticator app or a hardware key over SMS codes, which can be intercepted through SIM swap fraud. If a critical service offers no second factor at all, treat that as a reason to move away from it.
Step 4: Lock down money and identity
If financial data appeared in the leak, contact your bank directly using the number printed on your card rather than any number that arrives by message. Ask them to flag the account, and review the last three months of transactions for small test charges, which fraudsters use to check whether a card is live before attempting anything larger.
Where identity documents were exposed, watch for credit applications you did not make. Malaysian readers can request a CCRIS report from Bank Negara Malaysia to see what facilities exist in their name.
Step 5: Hunt for the infostealer
If the exposure came from an infostealer log, or if passwords you never typed into a breached site are appearing, assume a device is infected. Run a full scan with reputable endpoint protection, sign out of all sessions everywhere from each account's security settings, and change passwords only after the device is clean. Skipping this step is why people get re-compromised within days of cleaning up.
What to Do in the First Week
The immediate containment is done. The next phase is legal obligation and follow-up attacks.
Step 6: Report the incident
For individuals, report financial fraud to your bank and file a police report if money moved, since insurers and banks generally require one before they will process a claim.
For organisations in Malaysia, reporting is now mandatory. The Personal Data Protection (Amendment) Act 2024 brought breach notification into force on 1 June 2025, and the Personal Data Protection Guideline on Data Breach Notification sets out how it works. A data controller must notify the Personal Data Protection Commissioner as soon as practicable and no later than 72 hours after the breach occurs.
Read the trigger carefully, because the Guideline is not consistent with itself. Paragraph 6.1 states the limit as 72 hours "from the occurrence of the personal data breach". Paragraph 6.2 and its worked examples then compute the clock from the point you find out: when you are informed a device was lost, when you realise data went to the wrong recipient, or, for a suspected network intrusion, when inspection confirms the system was actually compromised. The notification form in Annex B asks the same way, whether you are filing "within the 72 hours after becoming aware". Work to awareness as the practical trigger, and treat the occurrence wording as the reason not to let a preliminary investigation drift for weeks.
Where the breach is likely to cause significant harm, affected individuals must then be told within seven days of that first notification to the Commissioner. Notification goes to the Commissioner through the JPDP portal or the Annex B form, and failure to notify carries a fine of up to RM250,000, imprisonment of up to two years, or both. Full text: the JPDP Guideline on Data Breach Notification. Our complete guide to PDPA compliance in Malaysia sets out the wider obligation set, including the DPO appointment requirement that arrived at the same time.
Seventy-two hours is too short a window to improvise in. Organisations that hit it have already decided who declares a breach, who drafts the notification, and who signs it.
Step 7: Expect the follow-up attacks
A leak makes you a known target. Within days, expect phishing messages that quote real details from the breach to establish credibility, and calls from people claiming to be your bank's fraud team asking you to "verify" a code. No legitimate bank asks for a one-time password. Anyone who does is running the attack.
Treat any unexpected contact that references the leak as hostile until proven otherwise, and verify through a channel you initiated yourself.
If the Dark Web Leak Involves Your Company
A corporate exposure is a different problem from a personal one, because one leaked employee credential can open the whole network.
Force a password reset for every affected account and revoke active sessions rather than relying on the reset alone. Check whether the exposed credentials were reused on any corporate system, including VPN, email, and administrative consoles. Review access logs for the affected accounts going back at least ninety days, since intrusions frequently predate discovery by months.
Then address the cause. If the leak came from an employee reusing a work password on a personal service, a policy document will not fix it. Ongoing security awareness training, phishing simulation, and monitoring that shows employees their own exposure will, because the behaviour changes when the risk becomes personal and visible. The structured response steps to take after a data breach cover the incident-management side in more depth.
Mistakes That Make a Dark Web Leak Worse
Four errors turn a contained incident into an expensive one.
- Changing one password and stopping. The breached account is rarely the target. The reused password on your email account is.
- Paying a "removal" service. No service can delete data from the dark web. Once a dump is distributed, it is copied indefinitely. Anyone promising removal is selling a fiction.
- Assuming an old breach is harmless. A password from a 2019 leak is dangerous today if you still use it anywhere. Age reduces relevance only if the credential changed.
- Ignoring it because "there is nothing valuable". Attackers aggregate. An address here, a phone number there, and a date of birth from somewhere else combine into enough for identity fraud. Our guide to preventing stolen data from being sold on the dark web covers how these fragments get assembled.
How to Reduce the Damage of the Next Leak
You cannot prevent a third party from being breached. You can decide in advance how much their breach costs you, and three moves go beyond the containment steps above.
Adopt passkeys where they are offered. A passkey replaces the password with a cryptographic key held on your device, so there is no shared secret sitting in anyone's database waiting to leak and nothing for a fake login page to capture. Google, Microsoft, Apple, and the mainstream password managers all support them now. This is the one control on the list that removes the failure mode described in this article instead of mitigating it.
Put your exposure checks on a schedule. A one-time lookup only reflects the corpora loaded up to that day, so checking once and considering the matter closed leaves you blind to everything published afterwards. Quarterly is a sensible floor for an individual. Companies need continuous domain monitoring, because new dumps surface every week and the value of an alert decays fast.
Act on vendor disclosures immediately. When a service you use announces its own breach, do not wait for the data to show up in a leak index, which can take months. Change that password the same day and check where else you used it. Acting inside that window costs you one password change; acting after publication costs a full compromise investigation.
In 2026, assume your details will land in a corpus sooner or later, and aim to make that entry worthless when it does. If you have not checked your own exposure since the last time you changed a password, start there.
Frequently Asked Questions
Can I remove my data from the dark web?
No, and any company promising removal is misrepresenting what is technically possible. Once data is distributed on the dark web it is copied across multiple sites and private collections, and no service can recall it. The workable response is to invalidate the data by changing credentials and enabling multi-factor authentication.
How do I know if my data is on the dark web?
Use a breach-checking service that indexes known leak corpora. Have I Been Pwned covers individual email addresses for free. Organisations need domain-level monitoring that watches every mailbox continuously, because one-off manual checks miss new exposures between searches.
Is it illegal to access the dark web in Malaysia?
Accessing the dark web or using Tor is not itself an offence in Malaysia, but the activities conducted there are. Unauthorised access to a computer system is an offence under the Computer Crimes Act 1997, while unlawfully collecting, disclosing, or selling personal data is an offence under the PDPA. There is no legitimate reason for an ordinary user to browse leak sites directly.
How long does leaked data stay dangerous?
Indefinitely, unless you change it. Passwords stay exploitable until replaced, and identity numbers such as an IC or passport number cannot be changed at all, which is why exposures involving identity documents require ongoing monitoring rather than a one-time fix.
What is the difference between a data breach and a dark web leak?
A data breach is the incident in which data is stolen from an organisation. A dark web leak is what happens afterwards, when that stolen data is published or sold. One breach can feed dark web leaks for years as the data is repackaged into new combolists.
