Dark Web Exposure Notifications: Admin Quick Reference

27th July 2026 | HowTo, MSP, Platform, Technology Dark Web Exposure Notifications: Admin Quick Reference

How to match each exposure to the right notification, and when to acknowledge it.

The Workflow

This is the full process for each exposure. There’s nothing to track beyond it.

  • Review the exposure card and check the “Data Exposed” field.
  • Match it to one of the categories below and use that notification text (edit as needed) in the Notify User box.
  • Click Notify User.
  • Check Acknowledge. This marks it as handled — remediation from here is on the user, not you.

Only un-acknowledged exposures need your attention. Once acknowledged, move on.

Matching Data Exposed to a Category

Data Exposed field shows…Category
Email addresses, Passwords onlyCredentials Only
Passwords + Usernames, Phone numbers, or similarCredentials + Account Details
The exposed account is the user’s actual email mailboxPrimary Email Account
Credit card data, Bank account details, PurchasesFinancial Data
Social Security numbers, Dates of birth, Physical addresses, Government IDsGovernment ID / Personal Info
Employee records, health data, internal documents (client’s own data)Company / Internal Data — escalate, don’t auto-notify

Credentials Only

Data Exposed shows: Email addresses, Passwords (nothing else)

Notification text:

Your email and password were found in a data breach from [Service Name] on [Date]. This is limited to that one account — no personal or financial information was involved. Please change your password there now, and turn on a passkey or two-factor authentication if the service offers one. If you used that password anywhere else, change it there too.

Credentials + Account Details

Data Exposed shows: Passwords plus things like Usernames, Phone numbers, or other account metadata (not government ID or financial data)

Notification text:

Your account details from [Service Name] were found in a data breach on [Date], including your password and some account information. Please change your password immediately, turn on a passkey or two-factor authentication, and update any security questions or recovery details tied to that account.

Primary Email Account

Applies when: The breach IS the person’s actual email mailbox (Gmail, Outlook, company email), not just a service that used their email as a username. Treat this one as more urgent than a typical credentials leak, since that inbox is usually the recovery path for everything else the person has.

Notification text:

This exposure involves your email account itself, not just another service. Please change your email password right away and set up a passkey or authenticator app right after. Also check your mail settings for any forwarding rules you didn’t create, and review your recent sign-in activity for anything unfamiliar. Since your other accounts may use this inbox to reset their passwords, treat this one as urgent.

Financial Data

Data Exposed shows: Credit card data, bank account details, or similar financial information

Notification text:

Your financial information was found in a data breach from [Service Name] on [Date]. Please contact your bank or card issuer now to request a replacement card or account number, and review recent statements for anything you don’t recognize. Consider placing a fraud alert with a credit bureau as an added layer of protection.

Government ID / Personal Information

Data Exposed shows: Social Security numbers, Dates of birth, Physical addresses, or other government-issued ID information

Notification text:

Your personal information — including [SSN / date of birth / address], as applicable — was found in a data breach from [Service Name] on [Date]. This is more serious than a password leak, since this kind of information can be used for identity theft. Please see the attached user guide for the specific steps to take, including placing a credit freeze and requesting an IRS Identity Protection PIN.

This is the one category worth pointing users to the full guide for, since there are several steps involved and they’re easy to get wrong on the fly.

Company / Internal Data

Applies when: The exposure is the client’s own internal data (employee records, health information, proprietary documents), not a third-party service breach. This doesn’t get a standard notification — flag it for the client’s leadership before sending anything to individual users, since it may carry legal notification requirements that a routine alert doesn’t.

A Note on the User Guide

A companion document, “What to Do If You Have a Dark Web Exposure,” is written directly for end users and covers the actual remediation steps (password changes, passkeys, credit freezes, and so on) in plain language. It can be attached or linked alongside any notification. Once the notification is sent, following through on those steps is the user’s responsibility.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

What Flock Cameras Teach Every Business About Data and Trust

What Flock Cameras Teach Every Business About Data and Trust

You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...

Read more
Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Tax season keeps accountants busy, and it keeps scammers busy too. Early this summer, a CPA firm became the...

Read more
The Ransomware an AI Model Built Without Trying

The Ransomware an AI Model Built Without Trying

Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...

Read more