AUTO-UPDATED

Why you can’t buy security on the dark web

Qrator Labs warns that businesses should avoid engaging with the dark web, as paying ransoms or purchasing stolen data fuels the cybercrime economy without guaranteeing security or recovery.

Key Points

  • The dark web functions as a mature B2B marketplace for stolen credentials, malware, and Ransomware-as-a-Service (RaaS) operations.
  • Paying ransoms is ineffective, as 80% of organizations that pay are targeted again, according to a 2021 Cybereason study.
  • High-profile cases like Uber and HBO demonstrate that paying attackers does not prevent the public release of stolen data or regulatory consequences.
  • Dark web monitoring often produces unreliable, noisy, or fabricated signals that cannot replace robust internal security controls.
  • Hiring anonymous actors for infrastructure audits creates significant risks, including the potential for unauthorized access and future exploitation.

Why it Matters

Directly engaging with the dark web incentivizes criminal activity and strengthens the infrastructure used to launch large-scale cyberattacks. Organizations should prioritize building internal cyber resilience through vulnerability management and incident response rather than attempting to negotiate with or pay malicious actors.
TechRadar Published by Andrey Leskin
Read original