Alert Recipients

Did you receive an alert from us?

If Darkweb IQ contacted you, the alert is real and it is meant to help. Our analysts collect threats targeting companies — exposed credentials, network access offered for sale, attacks in preparation — and as a matter of policy, when we find a credible threat targeting an organization, we try to warn them. We reached out so you can act before the threat is used against you.

This is not a phishing attempt.

We will never ask you for a password, a payment, or remote access to your systems. If you want to confirm a message came from us, contact us directly at [email protected].

The domains we send from

Every alert from Darkweb IQ comes from an address at one of these domains. Check the sender’s full address — not just the display name — and treat a message from any other domain as suspect.

  • @darkwebiq.com
  • @dwiqdisclosure.com
  • @dwiqnotice.com
  • @dwiqalerts.com
  • @dwiqreports.com

Who we are

Darkweb IQ is a pre-attack threat intelligence company. Our analysts work undercover inside the criminal networks that sell access to organizations, building direct, one-on-one relationships with the people offering it — so we learn who’s being targeted weeks before an attack runs. When a threat actor offers access to your network (an initial access broker), or when your employees’ credentials turn up in the infostealer malware logs that those same actors buy, we vet it and warn you while there’s still time to act. We are not the people who stole your data. We are the people trying to help you close the exposure before anyone can use it.

The alerts we send

We collect many kinds of threats targeting companies. If we contacted you, your alert was most likely one of these:

  • Exposed credentials. Passwords or session tokens tied to your organization surfaced in infostealer malware logs traded among criminals.
  • Your network access offered for sale. A broker is advertising or privately selling a way into your environment — often the step right before a ransomware attack.
  • An insider offering access or data. An employee, contractor, or partner is offering to sell their access to your systems or your data — or criminals are actively trying to recruit one of your people to do it.
  • Other threats naming your organization. Our analysts engage directly with the people behind these markets, and sometimes learn a company is being targeted before anything is listed for sale.

Whatever the type, the policy is the same: when we find a credible threat targeting an organization, we try to warn the affected party — customer or not, at no cost.

Our work with law enforcement

In January 2026, a Romanian national pleaded guilty to selling stolen access to networks, including Oregon state government offices. Darkweb IQ’s intelligence assisted that federal investigation.

“The Department of Justice acknowledges Darkweb IQ for its assistance with the investigation.”— U.S. Department of Justice, January 2026 (read the DOJ release)

Before his arrest, that same broker tried to sell access into 46 US hospitals. We warned all 46 in time — none were breached. We use the same sources and relationships that support law enforcement to protect everyday businesses that are being targeted.

Our responsible disclosure policy

When we find exposed credentials or access tied to an organization, we notify that organization directly and privately. Our goal is to reduce harm, not to create it. That means:

  • We disclose exposures privately to the affected organization, giving you the chance to remediate before the information can be exploited.
  • We do not publish, sell, or further distribute the credentials or access we identify.
  • We never demand payment in exchange for a notification, and we never hold information hostage.
  • We aim to give you enough detail to act — what was exposed and what to do — without exposing you to additional risk.

Why a password reset isn’t enough

If your alert was about exposed credentials, this part matters. Infostealer malware usually exfiltrates active browser session tokens in addition to passwords. Those tokens let an attacker authenticate directly to your systems — bypassing multi-factor authentication — and stay valid until they are explicitly terminated, even after the password has been changed. The malware can also persist on the infected device and recapture any credentials you rotate.

Attackers routinely use credentials from these logs to reach corporate environments through exposed services such as Citrix, RDWeb, VPN gateways, and VMware ESXi. That’s why closing the exposure takes three things together: rotating credentials, terminating sessions, and remediating the infected endpoint.

What to do next

The right steps depend on the type of alert, and your alert says which it is.

If your credentials were exposed

  1. Reset credentials for all affected accounts, prioritizing external-facing, privileged, and administrative access.
  2. Terminate all active sessions for the affected users across every system. This is separate from a password reset — stolen tokens keep working until you explicitly kill them.
  3. Investigate for unauthorized access, persistence, or lateral movement — assume the account may already have been used and work backward from there.
  4. Remediate the infected device. Identify and remove the malware (reimage if needed). If the device is personal or unmanaged and cleanup can’t be verified, treat it as compromised.

If your network access is being offered for sale

  1. Treat it as an attack in progress. A sale of access is typically the step right before ransomware deployment or data theft — assume the access works until you prove otherwise.
  2. Investigate the access vector described in your alert, and look for signs it has already been used.
  3. Review and restrict remote access pathways — VPN, RDP, Citrix, and similar external-facing gateways.
  4. Talk to us. Our analysts are in direct contact with the people selling this kind of access and can tell you more about the seller and your options — email [email protected].

If the alert concerns an insider

  1. Verify quietly — do not alert the individual. Confirm whether the person or account in your alert belongs to a current employee, contractor, or job candidate, and whether their identity was actually verified when they were onboarded or applied.
  2. Engage security, legal, and HR before anyone contacts the person.
  3. Preserve records — identity documents, application materials and interview recordings, payroll details, equipment shipping addresses, and account activity.
  4. Review the account’s access, then rotate credentials and terminate sessions before any contact is made. If the alert concerns a candidate, search your applicant tracking system and interview calendars, and pause any live candidacy or offer without tipping them off.
  5. Report it to the FBI via IC3.gov or to your national authority. Some insider schemes carry legal and sanctions exposure even when the employer was deceived — engage counsel early.

Questions? Reach out.

If you have any questions about a notification you received, or you’d like help understanding exactly what was exposed, email our intelligence services team at [email protected]. A real person will get back to you.

Want to see what’s circulating about your organization? Check your exposure →

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required