Dark Web Entities Explained: Who Really Operates in the Internet's Hidden Layer.

The Dark Web and Its Entities: A 2026 Research Guide | iMatrix
Digital Research Briefing — Updated August 2026

The Dark Web and Its Entities

A research-based look at who actually operates in the internet's hidden layer — from ransomware cartels to the journalists who rely on the very same anonymity.

iMatrix Research Desk 12 min read Cybersecurity & Digital Research
SURFACE WEB
DEEP WEB
DARK WEB

Illustrative, not to scale — see "What Is the Dark Web, Really?" below.

Type "dark web" into a search bar and you'll get two competing stories at once. In one, it's a lawless bazaar where anyone can buy a stolen credit card in three clicks. In the other, it's an overstated myth kept alive by crime dramas and clickbait. Neither is quite right. What actually exists behind Tor's onion-routed network functions much more like a hostile but organized economy — one with vendors, escrow systems, reputation scores, customer disputes, and, as of 2026, ransomware groups that have started running their own "legal departments" to pressure victims. Understanding who operates there, and why, matters more this year than it did five years ago, because the same infrastructure that hides a ransomware negotiator also hides a journalist's confidential source.

This briefing walks through both sides of that infrastructure: the entities that make up the dark web's underground economy, the researchers and law enforcement agencies working to dismantle parts of it, and the policy questions that are still, genuinely, unsettled.

What Is the Dark Web, Really?

It helps to think of the internet in three layers rather than one flat space. The surface web is everything a normal search engine can find and index — news sites, retail stores, this article once it's published. The deep web is everything sitting behind a login, paywall, or database query that search engines simply don't crawl: your email inbox, a hospital's patient records system, a university's journal subscription, your online banking dashboard. Most of what you do online every day already happens on the deep web, and none of it is inherently suspicious.

The dark web is a much smaller, deliberately hidden subset of that deep web. It isn't hidden by a login wall; it's hidden by design, reachable only through specific software that routes traffic through multiple encrypted relays so that no single point in the chain knows both who you are and what you're requesting. The Tor network (short for "The Onion Router") is by far the most common entry point, wrapping each request in layers of encryption — hence "onion routing" — that peel away one at a time as the traffic passes through independently operated relay nodes. Smaller, less-traveled networks like I2P and Freenet (now Hyphanet) serve similar purposes with different architectures, mostly for peer-to-peer file sharing and censorship-resistant publishing.

What the dark web is not is some vast, uncharted continent that dwarfs the visible internet. The number of active, meaningfully trafficked dark web marketplaces and forums at any given moment tends to number in the dozens, not millions — small relative to the surface web's index, even if the harm concentrated inside that small footprint is disproportionately serious.

Field note

Tor itself was originally developed with funding from the U.S. Naval Research Laboratory to protect government communications, and it's maintained today by the nonprofit Tor Project. The technology has no inherent allegiance to crime — it's a privacy tool that happens to be useful to criminals and non-criminals alike, in roughly the way a shredder or a locked filing cabinet is.

The Entities That Populate the Dark Web

"Dark web" isn't one thing, and neither are the entities running on it. Below is a working map of the categories that current threat-intelligence research keeps returning to, roughly ordered from the most overtly criminal to the most clearly lawful.

MarketplaceShifting, active

Multi-purpose marketplaces

Tor-hosted storefronts selling drugs, counterfeit goods, stolen data, and hacking tools through vendor profiles, escrow, and buyer reviews. Abacus Market dominated this category through 2024 before going offline in mid-2025 in what analysts widely assess as an exit scam; TorZon Market and STYX Market have absorbed much of the displaced traffic since.

Fraud platformHigh turnover

Carding and data-fraud shops

Platforms specializing in stolen payment card data, breached credentials, and infostealer logs — Russian Market and the now-seized BidenCash are the best-documented examples. Average marketplace lifespan across this category runs under a year before a seizure, exit scam, or rebrand.

RaaS forumSeized, Jan 2026

Ransomware-as-a-service hubs

Underground forums where ransomware operators advertise affiliate programs and recruit partners. RAMP (Russian Anonymous Marketplace) hosted promotion for LockBit, ALPHV/BlackCat, Qilin, and DragonForce before the FBI seized it in January 2026; the older XSS forum lost its administrator to arrest in Kyiv in mid-2025 after facilitating an estimated $7 million in illicit activity since 2018.

Ransomware groupActive

Ransomware-as-a-service cartels

Qilin overtook the field in 2025 with over a thousand claimed victims and has since added a self-described "legal department" and a multilingual call center to pressure non-paying targets. LockBit resurfaced under a new "LockBit5" build in late 2025 after its 2024 infrastructure takedown, publicly signaling interest in critical-infrastructure targets.

Access brokerGrowing

Initial access brokers

Specialists who breach a network, verify the access works, and sell it on — often to ransomware affiliates who never touch the initial intrusion themselves. Recent research tracking a single month of listings found professional-services and retail networks as the most commonly offered access, with a small handful of prolific sellers accounting for the majority of listings.

Hacktivist / state-linkedEvent-driven

Hacktivist collectives and nation-state actors

Politically or ideologically motivated actors who use dark web channels to coordinate, leak data, and claim credit. Geopolitical flashpoints reliably spike this activity — regional conflict in early 2026 saw dozens of hacktivist groups mobilize within days, alongside infrastructure-targeting operations attributed to state-linked units.

LegitimateLawful, active

Journalists and whistleblower platforms

Several major news organizations run onion-service mirrors and SecureDrop-style tip lines specifically so sources in hostile environments can share information without exposing their identity. This is, by most accounts, the dark web functioning exactly as its early designers intended.

LegitimateLawful, active

Privacy advocates and everyday users

Researchers, activists, and ordinary people living under censorship or surveillance use Tor to read blocked news, organize, or simply browse without being profiled. Independent estimates suggest a meaningful minority of onion sites host no illegal content at all.

The Dark Web by the Numbers

Numbers on the dark web should always be read with a healthy dose of caution — it's an environment built to resist measurement. Still, a consistent picture has emerged from recent threat-intelligence research.

+28%Growth in active dark web marketplaces during 2025, despite a record year of law enforcement takedowns
6.8moAverage lifespan of a dark web marketplace before seizure, exit scam, or voluntary shutdown
~75%Share of total marketplace transaction volume concentrated in just the top five platforms
16%Share of 2025 data breaches that involved AI tools on the attacker's side, per IBM's Cost of a Data Breach research

The pattern that ties these numbers together is resilience through fragmentation, not survival of a single dominant player. Every major seizure — Hydra in 2022, Genesis Market in 2023, Archetyp and BidenCash in 2025, RAMP in early 2026 — has been followed within weeks by displaced vendors and affiliates regrouping on a handful of successor platforms. The ecosystem behaves less like a company that can be shut down and more like a market that reroutes around damage.

Inside the 2026 Law Enforcement Offensive

Law enforcement's toolkit has matured considerably since Silk Road. Modern operations typically combine blockchain forensics to trace cryptocurrency flows, court-authorized Network Investigative Technique (NIT) warrants that allow investigators to identify specific Tor users, long-running undercover infiltration, and — increasingly — close coordination across multiple national agencies. The following sequence shows how that toolkit has been applied against the largest platforms in recent years.

OCTOBER 2013

Silk Road seized

The FBI shuts down the first major Tor marketplace after roughly two years of operation and over 100,000 users, establishing the template for future takedowns.

2017

Operation Bayonet

Coordinated international action dismantles AlphaBay and Hansa, two of the largest marketplaces to date, combining a covert takeover of Hansa with the AlphaBay seizure.

APRIL 2022

Hydra Market dismantled

German and U.S. authorities seize the Russian-language marketplace, the largest by transaction volume in dark web history at the time of its takedown.

FEBRUARY 2024

Operation Cronos

The UK's National Crime Agency and the FBI lead a multinational operation that seizes LockBit's infrastructure, freezes roughly 200 associated cryptocurrency wallets, and indicts its administrator.

JUNE 2025

Archetyp and BidenCash fall

Operation Deep Sentinel takes down Archetyp Market, a long-running European platform with roughly 600,000 users, in the same window that U.S. authorities seize the carding platform BidenCash.

JULY 2025

XSS forum administrator arrested

Ukrainian authorities arrest the alleged administrator of the XSS forum in Kyiv, with international support, disrupting a hub that had operated since 2018.

JANUARY–MARCH 2026

RAMP and LeakBase seized

The FBI seizes the RAMP forum, a key ransomware-promotion hub, in late January; the LeakBase forum, used to distribute exfiltrated data, is seized roughly six weeks later.

None of this has come close to ending the underground economy — but it has measurably raised the operational cost of running a platform, which is arguably the more realistic policy goal.

Is the Dark Web Illegal? The Policy Landscape

This is the question that generates the most confusion, so it's worth being precise. In the United States, the United Kingdom, Canada, and Australia, simply accessing the dark web through Tor is not against the law. The UK's Computer Misuse Act 1990, for example, targets unauthorized intrusion into computer systems — it doesn't criminalize anonymous browsing of content that's reachable within the Tor network itself. Courts and regulators across most democracies have consistently drawn the same line: the anonymity technology is neutral, and the law targets specific conduct — buying drugs or weapons, trading exploitative material, running fraud operations — rather than the network itself.

That doesn't mean the space is unregulated. Two policy trends stand out in 2026:

Conduct-based enforcement is intensifying

Rather than trying to block Tor outright — a strategy most security researchers consider technically impractical and politically fraught — agencies are investing in the targeted deanonymization tools described above: NIT warrants, blockchain analytics firms that trace laundering paths back to real-world cash-out points, and long-horizon undercover operations that can take years to mature into an indictment.

Compliance obligations are expanding

Separately from criminal law, a growing set of regulatory frameworks now expects organizations to actively monitor whether their own data has surfaced on the dark web. Provisions tied to GDPR, HIPAA, and standards like NIST and ISO 27001 increasingly treat dark web exposure monitoring as part of a reasonable security posture, and newer national laws — Chile's Ley 21.663 is a recent example — are being written with that expectation built in from the start. For organizations, this shifts dark web monitoring from an optional security nicety to something closer to a compliance checkbox.

Field note

International cooperation remains the biggest structural limitation on enforcement. A takedown that requires cooperation across three or four jurisdictions with different laws, evidentiary standards, and political priorities is inherently slower than the criminal infrastructure it's chasing — which is exactly why so many successful operations, from Bayonet to Cronos, have depended on multi-country task forces rather than any single agency acting alone.

Artificial Intelligence Enters the Underground Economy

The most significant shift in the underground economy over the past two years hasn't been a new marketplace — it's the arrival of generative AI as a criminal utility. Early tools like WormGPT and FraudGPT, marketed on dark web forums as unrestricted alternatives to mainstream chatbots, were mostly novelties in 2023. By 2026, researchers describe something more mature: AI embedded directly into criminal workflows, used to draft convincing phishing emails in fluent, native-sounding language, iterate malware variants faster than human developers could, and automate the reconnaissance work that used to precede an attack.

A second, less-discussed trend is the resale of legitimate AI access — stolen accounts and hijacked API keys traded the same way stolen streaming or banking credentials have been for years. It's the underground market following commercial AI adoption down a familiar path: wherever a technology becomes valuable enough, a secondary market in stolen access to it eventually appears.

The numbers back up the shift in emphasis. IBM's 2025 Cost of a Data Breach research found AI tools involved in 16 percent of breaches, split roughly between AI-generated phishing and deepfake-based impersonation, and industry forecasts suggest that share will keep climbing. Tellingly, most threat intelligence teams now describe AI's criminal role as a productivity layer rather than a replacement for human operators — accelerating routine tasks rather than running fully autonomous attacks, at least for now.

What This Means for You

For individuals, the practical takeaway isn't "avoid the dark web" — most people never go near it either way, and that has little bearing on whether their data ends up there. Credentials leak through breaches at companies you've never chosen to distrust. What actually helps is unglamorous: unique passwords managed through a password manager, multi-factor authentication wherever it's offered, and periodic checks through a reputable breach-monitoring service to see whether your email or financial details have surfaced in a known leak.

For organizations, three things matter more in 2026 than they did even two years ago. First, patch management has become a frontline defense against initial access brokers, whose entire business model depends on unpatched, internet-facing systems. Second, dark web monitoring is drifting from a discretionary security tool toward a compliance expectation under frameworks like GDPR and HIPAA. Third, and perhaps most urgently, staff training now needs to account for AI-generated phishing that no longer carries the grammatical tells people were taught to look for. "We're too small to be a target" stopped being a reasonable assumption once initial access brokers began commoditizing access to small and mid-sized networks alongside enterprise ones.

Frequently Asked Questions

Is it illegal to visit the dark web?

No. Accessing the dark web through Tor is legal in most countries, including the United States, the United Kingdom, Canada, and Australia. What's illegal is what you do once you're there — buying illegal goods, accessing exploitative material, or committing fraud. Courts have generally treated Tor as a neutral tool, similar to a VPN or an encrypted email service.

What's the difference between the deep web and the dark web?

The deep web is any part of the internet not indexed by standard search engines — your email inbox, a company intranet, a paywalled journal article. The dark web is a small, deliberately hidden subset of the deep web that requires specific software, most commonly the Tor browser, to access.

How large is the dark web compared to the surface web?

There's no reliable, universally agreed figure, and many widely repeated statistics on this point don't hold up well under scrutiny. What research consistently shows is that dark web marketplaces number only in the dozens at any given time, and even the largest platforms serve a fraction of the audience of ordinary e-commerce sites.

Can law enforcement actually track people on the dark web?

Yes, though it takes more work than on the open web. Agencies use blockchain forensics to trace cryptocurrency payments, Network Investigative Technique warrants to deanonymize specific targets, undercover operations, and international cooperation. The 2024 takedown of LockBit's infrastructure and the 2026 seizure of the RAMP forum both relied on exactly this combination of techniques.

Is everything on the dark web illegal?

No. Independent researchers estimate that a meaningful share of onion sites host no illegal material at all — secure tip lines run by news organizations, mirrors of censored websites, privacy-focused forums, and services used by people living under restrictive governments.

How can I find out if my information is on the dark web?

Dark web monitoring services and breach-notification tools, including ones built into many password managers and browsers, scan known marketplaces, forums, and leak sites for your email address, credentials, or financial details. Regulatory frameworks like GDPR and HIPAA increasingly expect organizations to run this kind of monitoring themselves.

Sources & Further Reading

  • Kaspersky Securelist — "Reviewing the Trends in Ransomware Attacks in 2026"
  • Group-IB — "Ransomware in 2026: Same Business, New Rules"
  • Emsisoft — "The State of Ransomware in Q2 2026"
  • Flare.io — "State of the Dark Web in 2026: Russian-Speaking Cybercrime Ecosystem"
  • Rapid7 — "Criminal AI-as-a-Service in 2026"
  • Cyble — "Dark Web Trends 2026: Ransomware, AI, and Cyber Threats"
  • Prey Project — "Dark Web Statistics & Trends for 2026"
  • IBM — "Cost of a Data Breach Report 2025"
  • U.S. Department of Justice — public case filings on dark web marketplace seizures

0 Comments