Why we built a dark-web monitor into ARK
Three weeks into ARK's first year, a user emailed us. She'd been in the Equifax breach. She had the credit monitoring, the breach alerts, the usual toolkit. What she didn't have was any way to know if her email address and payment details had already surfaced on the dark web, or whether they would in six months. She was checking Reddit forums manually. We knew we had to build this.
The gap nobody talks about
When someone finds out they're in a breach, the first thing they do is panic. The second thing is set up credit monitoring. Most people stop there. They assume that if their card gets cloned, they'll see it on their statement.
But that's not how it works anymore. A lot of the damage happens in the dark web, in forums and markets we can't see. Credentials get sold. Email addresses get packaged. Payment methods get tested and resold multiple times before they're used. The person who stole your data isn't sitting on it; they're actively trading it, sometimes years after the breach.
The problem is timing. You might be safe today. You might not be safe in nine months. And you have no way to know which.
Mobile users especially have this blind spot. Your phone is where the fraud happens now. Phishing links arrive as texts. Credentials are harvested by apps with loose permissions. Your financial apps are all on that device. But there was no simple way for a regular person to ask: is my information actually out there right now?
Building something that didn't feel like security theatre
The hard part wasn't the technology. Integrating with dark-web monitoring services is straightforward. The hard part was deciding what to do with the result.
We built dark-web monitoring into Shield because we wanted it alongside the other scans that matter. Your security score needs to account for breach exposure, not just app permissions and network leaks. A high score with your password already for sale on a forum is nonsense.
But we were careful about how we delivered the results. We didn't want to sell fear. We didn't want to nag you every time the monitor ran. We wanted it to be one input into your overall picture, something that fed into your action list without becoming the whole story.
The monitoring checks whether your email has appeared in new dark-web listings. If it has, you get a clear, actionable alert. If it hasn't, you get a clean result. And then you move on to the next scan. It's part of the system, not the system.
What the data actually told us
Once we shipped it, we started seeing patterns in how people reacted.
A lot of users already knew they'd been breached. They had the notification from HaveIBeenPwned or from the company itself. What they didn't know was whether that breach data had actually made it to the dark web. Some breaches get publicised but never traded. Others get stolen and immediately listed. The uncertainty was the problem.
Another group came to us from a different place entirely: parents. They wanted to know if their kids' emails had surfaced anywhere. Small business owners wanted to check personal emails they'd accidentally used on company devices. One user ran a freelance photography business and was monitoring five different email addresses at once, tied to different platforms and clients.
None of these use cases fit the old security model. They weren't corporate security teams running penetration tests. They were people with real exposure, no way to see it, and no way to know what it meant for their actual risk.
Dark-web monitoring became less of a feature and more of a permission. Permission to stop worrying in the background and start acting on real information.
Why it matters that you can see it on mobile
There's a reason most dark-web monitoring lives in desktop dashboards or credit-monitoring portals. It's traditionally been treated as something you check occasionally, like tax returns.
But your phone is the device that gets compromised. It's where you log in. It's where you authorise payments. It's where you receive phishing texts. So the breach alert needs to be there too.
We made sure the monitor runs on-device when possible, and that you see the result immediately. No waiting for an email notification three days later. No logging into another portal. You open ARK, you see your security score, and you see whether dark-web exposure is part of what's dragging it down. Then you act.
The remediation is one tap. If we find your email on the dark web, we link you to the relevant breach details and the steps you can actually take. Sometimes that's a password change. Sometimes it's enabling 2FA. Sometimes it's contacting the company. But it's always immediate and specific to your situation.
The bigger picture
Dark-web monitoring could have been a standalone feature. We could have sold it as a premium add-on and positioned it as the advanced option for paranoid users.
Instead, we bundled it into Shield because it felt wrong to treat breach exposure separately from the other ways your security can fail. Your device might have loose app permissions, but if your password is already for sale on the dark web, those permissions are the least of your problem. Your Wi-Fi might be leaking traffic, but if your email is already compromised, the Wi-Fi is a secondary concern.
The security score works because it treats all these things as part of one picture. Permissions matter. Network leaks matter. Breach exposure matters. They all feed into your number, and your number tells you where to start.
That's why a user who's been in a breach, or a parent worried about their kid's exposure, or a small business owner with five email addresses all see the same thing: a clear view of their actual risk, and a clear path to do something about it.
The original user who emailed us about Equifax still uses ARK. She runs a dark-web check every few weeks, and she sleeps better knowing whether her data has surfaced or not. That's not a dramatic feature story. But isn't that what security should actually do?