Blog
Cyber Threat Intelligence

From Social Media to Dark Web Forums: Monitoring Threats Across the Web

Cyber threats rarely start in hidden corners of the internet. Most begin in plain sight, on social media, before moving into Telegram channels and dark web forums. This blog looks at why organisations need visibility across the open and underground web, and how CYJAX connects the two into one picture of risk.

September 4, 2026
16
min read
Shail Yadav
Marketing Executive
Table of contents
Share

Key takeaways

  • Threats rarely start on the dark web. They usually start wherever an organisation has a public presence, most often social media.
  • Approximately 68% of fraud cases flagged to one major UK bank in 2026 started on a major social media platform, not the dark web.
  • Conversations frequently migrate from public platforms to Telegram. As a threat develops, these then move to closed forums and marketplaces.
  • Monitoring social media and the dark web separately leaves gaps. Treating them as one connected environment closes those gaps.
  • The real challenge is not collecting data. It is adding analyst context to prioritise what matters.

Your Organisation Is Being Discussed Online. Are You Listening?

Cyber threat intelligence is often associated with the dark web: hidden forums, Tor-only marketplaces, and encrypted chatter that most users will never see. That association is not wrong, but it is incomplete. Many of the earliest signs that an organisation is being targeted appear in public, on social media, in comment sections, or on paste sites long before they reach a criminal forum.

Approximately £1.28 billion was lost to fraud and scams in the UK in 2025, a 4% rise on the previous year, according to a 2026 UK banking industry fraud report. That scale of loss does not originate in a single place, rather it builds across platforms, and organisations that only watch the dark web are missing the part of the picture where a threat first takes shape.

The threat landscape isn't confined to the dark web

Threat intelligence has historically been framed around the dark web because that is where stolen data, credentials, and access get sold. However, by the time something reaches a marketplace listing, it has often already passed through several public stages.

Threat actors regularly discuss planned attacks, share leaked information, or promote scam campaigns in spaces that are technically public but not always fully open. A thread title or forum post may be visible to any visitor, but the detail behind it is frequently locked behind a free registration, a restricted membership tier, or a paid credit or token system. Brand Impersonation, phishing campaigns, and fraudulent accounts targeting employees or executives all tend to surface in these semi-public spaces first, often visible enough to flag as a risk before the fuller detail requires deeper access. As CYJAX has previously explored, threat actors have built entire service economies around boosting the reach of fraudulent adverts and fake accounts on mainstream platforms, making counterfeit campaigns look legitimate before a single victim is targeted.

The scale of this is significant. One major UK bank reported in June 2026 that 68% of fraud cases flagged by its customers started on a major social media platform. Separately, the UK's tax authority uncovered a suspected £153 million tax fraud scheme in which fraudsters used adverts on a short-form video platform to trick users into disclosing VAT and self-assessment details. Neither of these cases involved the dark web at any stage before the fraud was carried out.

Social media can provide early warning signals

Monitoring public platforms gives organisations a chance to catch problems while they are still forming, rather than after damage has been done. This includes:

  • Impersonation of executives, brands, or support accounts.
  • Scam campaigns using fake investment or job offers.
  • Phishing links shared in posts, comments, or direct messages.
  • Brand abuse, including counterfeit adverts and cloned pages.
  • Threat actor discussions referencing a specific organisation or sector.

Investment scam losses alone reached £221.5 million in 2025, which is up 40% year on year. A UK banking industry fraud report identified social media adverts promising unrealistic returns as one of the primary tactics behind this increase. These campaigns are visible to anyone looking, which is exactly why early monitoring matters. An organisation named in a fraudulent advert, or impersonated in a fake support account, has a window to act before the activity escalates or moves somewhere harder to reach.

What happens when the conversation moves underground?

Not every threat stays in public view. Once a threat actor has tested an approach, gathered interest, or needs to trade something of value, the conversation often shifts to more closed environments. These include Telegram channels, invite-only forums, and dark web marketplaces.

CYJAX has tracked this migration directly. In Behind Closed Channels: The Firearms Black Market on Telegram, analysts observed how Telegram has become a preferred venue for illicit trade precisely because it's more accessible than the dark web, requiring none of the operational security that dark web access demands. The same dynamic applies to fraud services, stolen data, and initial access sales.

As CYJAX outlined in Dark Web Explained: Risks, Benefits and the Importance of Dark Web Monitoring, the dark web remains a primary hub for trading stolen credentials, distributing malware, and selling access to compromised networks. Indicators of compromise frequently surface there before an organisation detects anything internally. As detailed in Dark Web Marketplaces 2026: Emerging Cybercrime Trends and Threats for CISOs, these marketplaces continue to grow in both scale and sophistication, trading everything from stolen credentials to zero-day access.

CYJAX specifically monitors criminal forums, Telegram channels, and threat actor marketplaces for emerging activity and leaked or commoditised data, tracking how threats develop once they leave the public eye.

Why monitoring one source isn't enough

The main problem with treating social media monitoring and dark web monitoring as separate activities is that threats do not respect that boundary. A single campaign might begin as a public discussion, move into a Telegram group to coordinate, appear on a criminal forum once data or access is ready to sell, and then develop into an active attack against an organisation.

Monitoring only the dark web means missing the earliest warning signs. Monitoring only social media means losing sight of a threat once it moves somewhere less visible. Threat intelligence is stronger when these environments are connected because context from one source often explains what's happening in another. This is the reasoning behind CYJAX's approach, as  detailed further in Dark Web vs Deep Web: What's the Difference and Why CISOs Should Care, which frames dark web monitoring as part of a wider, intelligence-led picture rather than a standalone activity.

From noise to actionable intelligence

Visibility across platforms is only useful if it can be acted on. The volume of chatter across social media, Telegram, and forums is significant, and the real challenge is not collecting information. It is identifying what matters, removing noise, adding context, and prioritising the risks that genuinely affect an organisation.

CYJAX's own research into phishing shows the scale of this problem. As explored in Phishing for Victims: The Cognitive Tricks Cybercriminals Use, over 40 million scam reports had been received by early 2025. This led to the removal of 214,000 scams across more than 387,000 URLs. Without analyst context, a figure like that is just noise. With it, it becomes a signal an organisation can act on.

This is the core of CYJAX's positioning: analyst-enriched, prioritised intelligence rather than raw data dumps. Connecting a public mention on social media to a Telegram discussion, and that discussion to a forum listing, turns three fragments of information into one clear picture of risk, which can be delivered before it becomes an incident.

FAQs

Frequently asked questions

Not by default. Dark web monitoring typically focuses on forums, marketplaces, and Tor-based sites. Social media requires separate visibility, which is why CYJAX combines both into a single intelligence approach rather than treating them as unrelated data sources.

Social media is open, fast to reach large audiences, and requires no special access. Threat actors use it to test scams, run fraudulent adverts, and impersonate brands before moving anything sensitive to a more closed environment.

Telegram is more accessible than the dark web and does not require the operational security that dark web access demands, which has made it a popular space for coordinating fraud, data leaks, and illicit sales. Dark web monitoring covers marketplaces and forums that require tools like Tor to access.

CYJAX analysts add context to raw data from across social media, Telegram, forums and dark web sources, filtering out noise and prioritising activity that poses a genuine risk to a specific organisation, rather than surfacing every mention.

No. Brand impersonation, phishing campaigns, and scam activity frequently begin on the open web. As such, brand protection needs visibility into public platforms and underground sources to catch threats at the earliest possible stage.

Subscribe for weekly updates

Receive our latest cyber intelligence insights delivered directly to your inbox

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share
Get started

Get Started with CYJAX CTI

Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.

Link Copied