Clients keep asking if their data is on the dark web. Here's what to actually tell them.
It usually arrives as a forwarded email. A client saw a breach headline, or got one of those "your credentials were found on the dark web" marketing blasts from a vendor they've never heard of, and now there's a one-line question sitting in your inbox: are we on there?
If you run an MSSP, that email starts a clock. Too slow or too vague and the client starts wondering what else you're not watching.
The problem is that the question, as asked, doesn't have a yes/no answer. Here's how to give a good one anyway.
"The dark web" is not really the thing to check
Say "dark web" and your client pictures a hoodie and green terminal text. What's actually out there is duller. Stolen databases from breached companies. Old leaks stitched together into compilations. Logs scraped off somebody's infected laptop. It changes hands on forums, on Telegram, over plain old file-sharing links, and a lot of it never touches Tor at all. The plumbing is not exotic, and that matters, because unglamorous things can be checked.
Which is good news for you. It means the honest version of the client's question is one you can actually answer with data: have email addresses on their domain appeared in known breaches? Which breaches, how recent, and what was exposed alongside those addresses?
That reframing, said out loud to the client, already makes you sound like the adult in the room.
The honest answer has three parts
Part one: the base rate. Some of their addresses almost certainly appear somewhere. As of August 2026 our index holds 773 breaches and over 11.5 billion records. At that scale, betting on a completely clean sheet is unrealistic for a company domain of any size. Say this plainly and early. It stops the panic, because the raw fact of appearing in a breach index is the base rate, not the emergency.
Part two: the details that matter. An address in a 2016 compilation of recycled leaks and an address in a breach added last month are two different conversations. What you owe the client is the breakdown: which breaches, what data classes went with the email (just the address? phone numbers? IDs?), and how recent. That breakdown is the difference between reassurance and an action plan. And when the client's next question is "where does this data come from?", don't improvise. Our sources and verification process are public at /our-data. Send the link.
Part three: what happens next. A one-time check answers today's question. Monitoring answers the question they'll have every time the next headline lands. This is where the awkward inbox moment quietly becomes a service line.

A script you can reuse
Adjust the middle to your actual findings:
"Some of your company email addresses appear in past data breaches. That's the normal state of things, so the count by itself isn't the story. We've pulled the full picture: which breaches, what data was exposed, and how recent. Two items are worth acting on, and here's our plan for those. Going forward we monitor your domain continuously, so when anything new appears, we tell you before you have to ask us."
Notice what the script doesn't do. It doesn't dramatize. It doesn't drown the client in numbers. And it ends with the ongoing relationship, not the scare.
Since the question usually lands as an email, here's the reply version too:
Good question, and one we can answer with data rather than guesswork.
Short version: a few of your company addresses show up in older, publicly known breaches. That's the normal state of things, so the count alone isn't the story. What matters is which breaches, what was exposed, and how recent.
We're pulling the full breakdown for your domain now and will walk you through it on our next call. If anything in it needs action before then, you'll hear from us today.
Two paragraphs, no drama, a promise with a deadline. That's the whole trick.
Four things not to say
"You're safe." You can't promise that, and the client will remember the promise, not the caveats.
"We scan the dark web in real time." Only if that's literally true of your stack. Overclaiming here is how trust dies during the next incident.
"11.5 billion people have been breached." Records are not people. The same person shows up in breach after breach, and compilations keep recycling records that leaked years ago. Being precise here is exactly what separates you from whoever sent that scary email.
Nothing at all. The worst answer. If you say "we'll get back to you" and a competitor shows up with a domain exposure report the same week, that RFP conversation is already over.
Turning the question into a deliverable
The playbook here is simple. The client question becomes a baseline exposure report (here's everything on record for your domain, explained in plain language). The report turns into a monthly monitoring line item, and the monitoring is what carries the renewal conversation, because you now show up quarterly with "here's what we caught for you."
Here's what that looks like in practice. This is the domain view from our console: three monitored domains and their exposure counts in one screen. In the MSSP product, views like this carry your brand, not ours:

None of this is hypothetical, either. DigitalTrack already runs domain monitoring for its clients; their story is in our case studies.
And none of it requires you to build breach intelligence yourself. It requires having the data when the question arrives.

Where to start
Check your own domain first. Every company can see and monitor its own breach exposure on XposedOrNot free, forever. That's the pledge, and it shows you the same breach-exposure picture your clients would get.
When you're ready to offer the same picture to clients under your own brand, that's what xonThreatIntel+ for MSSPs does: white-label domain monitoring across your client portfolio. Legacy threat intel platforms were built for Fortune 500 budgets. Partner plans here start at $99/mo with monthly billing and no lock-in, live the same week you sign up.
The next client email about the dark web doesn't have to be an awkward one.
Appendix: Sources and references
- Breach and record counts: our public catalog , 773 breaches / 11.5B+ records as of August 11, 2026, queryable keyless at
api.xposedornot.com/v1/breaches - Free self-monitoring: xposedornot.com (free for your own domain, forever)
- MSSP mode details: plus.xposedornot.com/products/threat-intel/mssp