DARK WEB SCANNING
Bryan Pryor
Partner, vCIO
Pathway of Disaster
WHAT IS THE DARK WEB? • A Hidden Universe contained within the “Deep Web” – sublayer of the Internet • Search Engines like Google, BING, Yahoo only search 0.4% of the indexed or “surface” internet. • The other 99.6% of the web consists of databases, private academic and government networks and THE DARK WEB. • The Dark Web is estimated 550 time larger than the Surface Web. • You can operate Anonymously = illegal activity.
HOW DOES KNOWING HELP YOU • If you chose to monitor the Dark Web for your business credentials, you will quickly know when they show up for sale on the Dark Web. • Change your passwords immediately to something complex and very different from the password stolen. • Breaches are typically not discovered for months after the breach occurs. This provides a proactive method to reduce the likelihood of being a victim.
WHAT IS INCLUDED IN THE SCAN? • The data discovered is verified • Some sources don’t guarantee if the data is real or fake
• Not just an email address • Includes the associated PASSWORD • Includes the source of the breach, once acknowledged by the victim
• Data harvested from sites that require credibility or membership within the hacker community. • Available for ongoing monitoring and alerting
HOW IS THE DATA STOLEN? • Keylogged or Phished • Data was entered into a fictitious websites or extracted through software designed to steal PII
• 3rd Party Breach • Data exposed as a part of a company’s internal data breach or a 3rd party website.
• Accidentally exposure • Data accidentally shared on a web, social media or peerto-peer site
• Malicious • Data was intentionally broadcast to expose PII
ENCRYPTED DATA • Many site encrypt your password • Encryption is better than clearly seen • Encrypted passwords can be unencrypted using websites like https://crackstation.net/ • This is an example of an encrypted password C0a20267f9f1e4469f8eb7bf45704218293412db • This is an example of breaking the code
FREE 1-TIME DARK WEB SCAN • Enter your work email to scan your business domain. • One per business • https://www.integrityky.com/free-dark-webscan/ • Results are reviewed in a confidential meeting
WEEKLY CYBER SECURITY TIP EMAIL • Sign up online • https://www.integrityky.com/my-security-tips • Unsubscribe anytime