Dark Watch Monitor โ Live Dark Web Intel
A security camera pointed at the dark web. We watch scam forums, leak sites, and fraud marketplaces so you don't have to.
๐ก๏ธ Why This Matters to You
Stolen logins, credit cards, and personal info from UK victims are traded on the dark web every day
We flag threats targeting UK families, businesses, and schools โ not generic international data
New scam campaigns appear on the dark web weeks before they hit your inbox. We spot them first
No paywall, no subscription. The same intel that security firms charge thousands for โ free to the public
๐ก Monitor Status
๐ Dark Web Intelligence Summary
LLM-analysed summary of today's dark web monitoring activity. Generated: 2026-09-11
Our dark web monitoring pipeline is actively tracking 39 targets. 0 targets classified as high risk and 5 as critical. This includes ransomware leak sites, stolen credential markets, and active threat actor forums.
Classifications by LLM (qwen2.5:1.5b). Updated daily. View full LLM brief โ
๐ How It Works
All requests route through anonymised Tor exit nodes
BTC wallets, emails, domains, IPs, phones, onion URLs extracted from every page
Every capture stored with content hash, change detection, and raw HTML
Automatic alerts when monitored targets change or new entities appear
๐งช Methodology โ Total Transparency
No black boxes. Here is exactly what DarkWatch does, where the data comes from, how it is checked, and what every status actually means.
- Ransomware leak sites and victim listings (UK-focused)
- Phishing kits & scam infrastructure targeting UK banks
- Newly discovered .onion services via Ahmia search index
- Tor network health (relays, exit nodes, bandwidth, users)
- Stolen-data marketplaces and fraud forums where reachable
- UK organisations named on ransomware.live leak feeds
- Automated pipeline runs on a schedule (typically hourly)
- All .onion traffic routed through anonymised Tor proxy
- Public APIs & feeds: ransomware.live, Ahmia, Tor Metrics, Archive.today
- Entity extraction: BTC wallets, emails, domains, IPs, phones, onion URLs
- Every capture stored in SQLite with content hash + change detection
- Every source is health-checked each run (๐ข operational / ๐ก degraded / ๐ด down)
- Staleness detection: if a feed stops updating we say so โ we never fake fresh data
- Findings cross-checked against multiple feeds where possible
- UK victim claims are matched to the leak-site listing and the feed metadata
- Anything marked HIGH/CRITICAL is manually reviewed before it is surfaced
- LIVE / Active: fresh, machine-readable evidence found at the source during the current monitoring cycle
- Inactive / never: no new activity since we started watching โ the site may be offline or taken down (e.g. by NCA/FBI operations)
- Threat level: Critical โ High โ Medium โ Low, based on type, activity, and corroborated intel
- IOCs: indicators of compromise extracted from pages (domains, wallets, emails, hashes)
- A leak-site listing is a claim by the group โ we label it as reported, not as independently confirmed victim data
Every panel shows its own check time (๐). If a source is stale, a warning banner appears at the top of this page โ we display the last known good data rather than inventing numbers.
Full pipeline update: loadingโฆ
- ransomware.live โ leak-site victim feed
- Ahmia โ .onion search index
- Tor Metrics โ network health
- Archive.today โ snapshot capability
- Direct .onion captures via Tor proxy + Dread/forum intel where reachable
- Alert delivery via configured mail relay (msmtp)
๐ฌ๐ง UK Ransomware Victims โ ransomware.live
Live feed of UK organisations listed on ransomware leak sites. Data sourced from ransomware.live.
Top Ransomware Groups Hitting UK
Top Industries Affected
Recent UK Victims
| Victim | Group | Date | Industry |
|---|---|---|---|
| RelyComply AML Platform | direwolf | 2026-09-09 | Financial Services |
| copeplastics.com | chaos | 2026-09-08 | Manufacturing |
| Brent Electric | akira | 2026-09-08 | Energy & Utilities |
| Ben Leeds Properties | ShadowByt3$ | 2026-09-07 | Other |
| The Big Table | qilin | 2026-09-05 | Hospitality |
| Schwartz, Giannini, Lantsberger & Adamson (SGLA) | spacebears | 2026-09-04 | Professional Services |
| Marlborough Partners | anubis | 2026-09-02 | Financial Services |
| Manchester Airports Group | fulcrumsec | 2026-09-01 | Transportation |
| The Sole | thegentlemen | 2026-08-31 | Retail & E-Commerce |
| www.lichtvision.com | incransom | 2026-08-31 | Technology |
| Absolute Consultancy Services | qilin | 2026-08-30 | Professional Services |
| macallister.com | chaos | 2026-08-28 | Not Found |
| MB Associates | thegentlemen | 2026-08-28 | Professional Services |
| Brebur | thegentlemen | 2026-08-28 | Not Found |
| Whitehouse | qilin | 2026-08-28 | Government & Defense |
| LGG Advisors | qilin | 2026-08-27 | Professional Services |
| DAB Investments | qilin | 2026-08-27 | Financial Services |
| Displaydata | qilin | 2026-08-27 | Technology |
| hatch.group | settra | 2026-08-27 | Professional Services |
| Metal Conversions | qilin | 2026-08-26 | Manufacturing |
| Morgan Services | AiLock | 2026-08-26 | Professional Services |
| Air International Thermal Systems | qilin | 2026-08-26 | Manufacturing |
| Party Rental | thegentlemen | 2026-08-25 | Hospitality |
| A-Plus Software Limited | ShadowByt3$ | 2026-08-25 | Technology |
| Knottingham Trent University | ShadowByt3$ | 2026-08-25 | Education |
๐ฃ Phishing Kit Intelligence
Phishing kit mentions from live phishing URL feeds and dark web monitoring. UK bank names are specifically monitored.
๐ Data Sources
Dark Watch pulls intelligence from these live sources:
๐ฐ Cybersecurity Headlines
Curated from 2 sources via DarkWatch, OnionClaw, and IntelX enrichment.
37084 threats tracked. Sources: DarkWatch, OnionClaw, IntelX. View daily brief โ
๐ Recent Dark Web Intelligence
Real captures from our dark web monitoring pipeline โ data is being actively collected from Tor hidden services and threat actor infrastructure.
10 recent captures monitored. Pipeline updates every 60 minutes via Tor-routed fetches. View full table โ