Prerequisites
01
The dark web is a legal environment, not a lawless one
Investigators who treat the dark web as inherently off-limits miss evidence that is publicly accessible under the same legal frameworks that govern open-web research. Those who treat it as a consequence-free zone face prosecution, professional sanction, and source compromise.
The dark web is a collection of networks, principally Tor onion services, that require specific software to access. It is not illegal to visit. The distinction that matters is not which network you use but what you do on it: the same acts that are illegal on the open web are illegal on the dark web, and vice versa.
What changes is the risk profile. Operational security failures that are minor on the open web can expose sources or trigger law enforcement attention. The legal frameworks governing your work (GDPR, the CFAA, the UK CMA) do not switch off when you connect to Tor. Understanding where the legal lines sit is the prerequisite for dark web investigative work.
In the field
On 8 November 2024, Finastra, a financial software and services provider to 45 of the world's top 50 banks, notified customers that a threat actor had communicated on the dark web claiming to have exfiltrated data from its internal file transfer platform. Security journalist Brian Krebs reported the incident publicly on 19 November, before which no public disclosure had been made.
- Threat intelligence forum capture. The seller listed data from Finastra's banking clients on the cybercrime forum BreachForums on 31 October and again, naming Finastra directly, on 8 November; screenshots of both listings were captured by the threat intelligence platform Ke-la.com.
- Source corroboration. A Finastra customer independently shared a copy of the company's internal disclosure notice with Krebs, corroborating the threat actor's claim from a second, non-public channel.
- On-record confirmation. Finastra provided a written statement confirming the incident and its response, stating that initial evidence pointed to compromised credentials.
KrebsOnSecurity · Fintech Giant Finastra Investigating Data Breach · 19 November 2024
Learning outcomes
By the end of this tutorial you will be able to:
Identify which actions on the dark web are legally equivalent to open-web actions and which carry additional legal exposure
Apply the Computer Misuse Act (UK), CFAA (US), and GDPR Article 6 frameworks to specific dark web investigative scenarios
Distinguish between passive access (lawful in almost all jurisdictions) and active interaction (requires case-by-case legal review)
Construct a compartmentalised Tor access environment that does not expose real IP, device identity, or institutional affiliation
Document dark web evidence to an evidentiary standard acceptable in UK and EU court proceedings
This tutorial is for Signal subscribers.
Methods goes deep on a single technique each fortnight. The decision framework, the tools, the failure modes, and the evidentiary standard required to use the finding defensibly.
Join SignalA Signal subscription gives you:
- Full OSINT Reference Card library
- Methods, all tradecraft tutorials in full
- Shadow Analysis, all evidence-based reporting
- Forensic Dossiers, full access
- Discord access included


