By Alex Holden, Chief Information Security Officer Hold Security
For nearly two decades I made the Dark Web a place to be; however, I am a hacker nor a cyber threat actor. I am a cyber threat intelligence professional with a deep passion for cybersecurity.
After spending a decade in the 2000s in corporate security, I realized that as a CISO, I neglected to understand the enemy. The bad guys who are actually trying to hack our systems.
We spent significant amounts of time and resources building defenses. We worried about vulnerabilities, malware, compliance, firewalls, authentication, policies, and the latest technologies promising to make us more secure. But too many of our efforts were driven by reactions to ongoing attacks, fears, industry headlines, and sometimes fear-mongering from vendors.
We were looking at cybersecurity almost entirely from our side of the battlefield.
Turning my eyes toward the Dark Web helped me understand the enemy and scale defenses to the actual threats and approaches being used against us.
Just think about how quickly technology evolves. Tools change. Encryption changes. Evasion becomes more sophisticated. Infrastructure becomes distributed and disposable. Today, AI is accelerating portions of that evolution even further. Our ability to defend gets tougher because the technology on both sides continues to change.
What stayed relatively static?
The threat actors themselves.
They are people too and they dwell amongst us in our society. They make mistakes. They have goals and motivations. They have egos. They need money or information. They trust the wrong people. They get angry. They compete with each other. They brag about success and complain about failure.
And criminals need other criminals.
A successful cyberattack is rarely just somebody sitting alone in a dark room wearing a hoodie. There is an ecosystem behind cybercrime. Someone develops malware. Someone finds vulnerabilities. Someone obtains access. Someone sells access. Someone steals information. Someone launders money. Someone negotiates ransomware payments. Someone buys the stolen data.
Those relationships create intelligence opportunities.
Going to the Dark Web gave me an opportunity to learn about the enemy and gave me more tools to deter and prevent cyberattacks and breaches.
It also taught me that you cannot understand cybercrime simply by collecting indicators of compromise.
An IP address can tell you where something happened. A malware sample can tell you how something works. Logs can tell you what happened inside your environment.
But none of those necessarily tell you why you were attacked, what the criminal was looking for, what they succeeded in taking, what they plan to do next, or whether they are coming back.
For that, sometimes you need to understand the people behind the attack.
Running a diverse team that engages threat actors and keeps an eye on the pulse of the Dark Web allowed us to discover and investigate many of the highest-profile breaches of all time.
Sometimes it means getting inside a ransomware gang and understanding how they function. Who actually makes decisions? How do they choose victims? How much information do the people negotiating with the victim really have? If a victim pays, should they rely on the word of criminals that the stolen information will really be deleted?
Sometimes it means understanding the threat actor’s view of a breach. Companies naturally investigate incidents by looking inward. What systems were compromised? What logs exist? What data could have been accessed?
But attackers may already be talking about what they actually obtained.
That creates a completely different perspective.
There is an enormous difference between information that could have been stolen and information that actually was stolen. There is also a difference between what criminals claim to have and what they really possess. Understanding that difference requires more than automated monitoring. It requires context, history, access, and understanding how these communities operate.
The same applies to tracking nation-state threat actors. Their motivations are different, but they are still people operating within organizations and relationships. Watching their dynamics, infrastructure, interests, tools, and targets helps us understand not only what happened yesterday, but what may become important tomorrow.
There is another misconception about the Dark Web that is especially important.
There is a lot of stolen data on the Dark Web, but data stolen does not always translate to data abused.
That distinction creates opportunity.
Credentials may be stolen before somebody uses them. Corporate access may be offered for sale before ransomware operators purchase it. A database may circulate privately before criminals figure out how to monetize it. Sensitive information may appear in one criminal community before spreading into many others.
Once data has been weaponized, our options become much more limited.
Before that happens, there may still be time.
We can reset credentials. Disable accounts. Investigate compromised systems. Change access rights. Notify organizations. Watch for fraud. Understand how the compromise happened and prevent the next stage of the attack.
This is one of the reasons simply searching the Dark Web for a company name is not enough.
The real question is not just, “Is our data there?”
The questions are: Who has it? Where did it come from? How recent is it? Is it legitimate? Who else is interested in it? What can they do with it? And perhaps most importantly, what are they likely to do next?
That is where information starts becoming actionable intelligence.
The Dark Web has changed considerably during the years I have been watching it. Communities disappear. Criminal marketplaces get seized. New communication platforms replace old ones. Criminals move between public forums, private channels, messaging applications, invitation-only communities, and direct relationships. Artificial Intelligence…
The location changes.
The need for criminals to communicate, collaborate, sell, buy, recruit, and monetize does not.
That is why understanding the Dark Web is not about knowing the address of a few criminal forums. It is about understanding the ecosystem.
The bottom line that every cybersecurity professional needs to be aware of is that the Dark Web is a pulse of cybercrime.
Ignoring it today is dangerous.
You do not need to become a Dark Web investigator yourself, but somebody in your security strategy needs to understand what is happening outside your network, not just what your security tools are telling you from inside it.
I learned a long time ago that defending only from your own point of view leaves a significant blind spot.
Therefore, I go to the Dark Web every single day.
To understand the enemy. To see what is changing. To find opportunities before vulnerable or stolen information becomes weaponized. To defend. To deter.
And to make the cyber world a bit better.

