What to Do If Your Information Is on the Dark Web: The First 72 Hours
A dark web alert tells you something is out there and almost never tells you what to do about it. Here is the ordered checklist, sorted by what actually leaked, with the free steps first.
See what is published about you before you read on
The scan checks the data brokers and people-search sites in our catalog for your name and shows what each one publishes. No account needed.
No account needed. Adding a city and state is what lets us tell your record apart from everyone who shares your name.
If your information is on the dark web, do not try to delete it, because that is not possible. Neutralize it instead. In the first 72 hours: change every reused password, ask your card issuer for a new number, freeze your credit at all three bureaus for free, add an IRS Identity Protection PIN if your Social Security number was exposed, and set a port-out PIN with your phone carrier. Those five steps convert most stolen records into worthless ones. Everything after that is about cutting off the surface-web data that makes a leak usable in the first place.
The alerts themselves are not much help here. A bank, an antivirus subscription or a breach notification letter will tell you that your data has appeared somewhere, and then stop. It rarely says which breach, how old the record is, or which of your accounts is now at risk. That gap is why so many people either panic and buy a subscription they do not need, or shrug and do nothing. Neither is the right response, and the correct one takes about an evening.
What does it mean when your information is on the dark web?
It means a copy of some record about you is being traded on sites that are not indexed by search engines and are reachable only through anonymizing networks. In practice that record came from a company that got breached, or from malware on somebody's laptop that scraped saved logins. It sits in a file alongside millions of other people, gets resold, repackaged and mirrored, and no single party controls it.
What it does not mean is that someone is actively targeting you. The overwhelming majority of dark web exposure is bulk data nobody has looked at individually. That matters for how you should feel about it, but not for what you should do, because bulk data gets run through automated credential stuffing and account takeover attempts regardless of whether a human ever reads your name.
What should I do first if my info is on the dark web?
Work in order of what can be invalidated fastest. A password can be made worthless in thirty seconds; a Social Security number never can, so it needs a different kind of defense. Sorting the exposure by type before you act is the single thing that separates a productive evening from an anxious one.
| Hour | Action | Cost |
|---|---|---|
| 0 to 2 | Change every password you reused anywhere, starting with email, then banking, then everything tied to that email for password resets. Turn on a passkey or an authenticator app where offered. | Free |
| 0 to 2 | Call your card issuer and ask for a new card number if any payment data was named. One phone call kills the value of the stolen record instantly. | Free |
| 2 to 24 | Freeze your credit at Equifax, Experian and TransUnion. Federal law makes this free at all three, it does not affect your score, and each bureau must be frozen separately. | Free |
| 2 to 24 | If your Social Security number was exposed, request an IRS Identity Protection PIN so nobody else can file a tax return under it. | Free |
| 24 to 48 | Add a port-out PIN or account passcode with your mobile carrier so a SIM swap fails at the counter. This is the step that protects every account using SMS codes. | Free |
| 48 to 72 | Remove your address, phone and relatives from data broker and people-search sites, which is the data that makes the rest of the leak usable. | Free to do yourself |
Notice that every row costs nothing. There is a version of this checklist sold as a product, and the paid version does not do anything the free version cannot, with one exception covered further down.
Why is freezing your credit the most important step?
Because it blocks the outcome rather than reporting it. Monitoring tells you after someone opened a credit line in your name. A freeze means the lender cannot pull your report at all, so the application fails before it starts. It is the only step on this list that prevents the specific harm most people are afraid of.
The common objection is that a freeze will be a hassle when you actually want credit. That is much less true than it used to be. Bureaus are required to lift a freeze within one hour when you request it online or by phone, so you can thaw it from your phone while sitting across from a loan officer. It stays in place until you lift it, and there is no fee to place, lift or remove it at any of the three bureaus.
How did my information get on the dark web?
Almost always through a company you trusted with it, not through anything you did wrong. Retailers, health systems, hotel chains, payroll providers and background check firms all get breached, and their disclosure letters are how most people find out. The second common route is infostealer malware, which quietly harvests every credential saved in a browser and sells the bundle. The third is credential stuffing lists assembled from older breaches, which is why reused passwords are so dangerous.
This is also why a new alert usually is not a new theft. Old dumps get recombined and resold as fresh collections for years, so the same record can resurface half a dozen times. Judge your risk by whether the identifiers are still valid, not by the date on the alert.
Can I remove my information from the dark web?
No, and this is worth being blunt about because a lot of marketing implies otherwise. There is no registrar to complain to, no hosting provider that answers legal notices and no operator with any obligation to comply. Every service advertising dark web removal is really selling monitoring, insurance, or removal from the ordinary web. We wrote up exactly what dark web removal can and cannot do, including a table of what each major provider actually delivers for the money.
The part that genuinely can be removed is the half nobody talks about. Your current address, phone number, age and the names of your relatives are published legally and openly by data broker and people-search companies, and those companies do have to honor a removal request. That is not a technicality. A Social Security number in a dump is nine digits until somebody can attach it to a real, current person, and the attaching data comes from brokers, not from the dark web. Cutting that supply is the one removal actually available to you, and the people-search opt-out guides walk through each site's form.
What happens if your information is on the dark web?
For most people, nothing visible. The realistic risks, roughly in order of likelihood: credential stuffing against accounts where you reused a password, phishing and scam calls that sound credible because the caller knows your address and your bank, a fraudulent tax return filed early in the season, a SIM swap that captures your SMS codes, and at the far end, new credit opened in your name. A freeze and unique passwords take the last two mostly off the table.
Medical identity theft deserves a separate mention because it surfaces late and is the hardest to unwind. If insurance or member ID numbers were exposed, ask your insurer for a record of claims paid under your policy and read the explanation of benefits for care you never received.
How do I know if my information is on the dark web?
Run a free breach lookup against your email addresses, including the ones you abandoned years ago. Forgotten accounts are usually the ones still carrying a reused password, and they are the accounts nobody thinks to check. If you have accumulated a decade of sign-ups across several old addresses, it helps to bring those mailboxes into one place before you start, otherwise the audit stalls at the second forgotten login.
One option people used to rely on is gone. Google shut down its free dark web report in 2026, stopping new scans on January 15 and removing the report itself on February 16. Google's own reasoning is telling: the company said the tool was informative but did not give people clear next steps, so it chose to focus on features that come with actionable guidance. It pointed users toward passkeys and toward removing personal information from Search instead.
Do I need to pay for dark web monitoring?
Usually not, and this is the exception mentioned earlier. Monitoring only tells you something you can already learn for free, and a credit freeze prevents the outcome a monitor would merely report to you afterward. Your bank and card issuer already alert on suspicious activity at no charge. If you were offered free monitoring in a breach letter, take it, but do not renew it out of habit.
The subscription that does earn its cost is the recurring one, because the surface-web half of this problem does not stay fixed. Broker sites re-import public records on a schedule and rebuild your profile from a file that never saw your opt-out, so a listing you removed in March is often back by summer. That is a maintenance job rather than a hard one, which is the honest case for paying somebody to repeat it. Our breakdown of what a data removal service costs compares the tiers without the affiliate math.
What are the signs it is already being used?
Watch for a credit card or loan you did not apply for appearing on your report, a tax return rejected as already filed, mail from a debt collector about an account you never opened, your phone abruptly losing service, or password reset emails you did not request. Any one of those means move past prevention and start the recovery process.
At that point, file at the FTC identity theft site before you begin disputing anything. It generates a recovery plan and an official identity theft affidavit, and creditors will ask for that affidavit. Getting the paperwork order right is the difference between a two week fix and a six month one.
The short version
You cannot delete anything from the dark web, so stop trying and spend the effort where it changes something. Invalidate what can be invalidated, and almost all of it is free: passwords, card numbers, credit freezes, an IP PIN, a carrier port-out PIN. Then take down the openly published address and phone records that let a stranger turn a leaked identifier into a convincing impersonation of you. Our guide to removing your information from the internet covers that second half in full, and the data broker opt out list names the companies to start with.