• Skip to main content
  • Skip to primary sidebar

Criminal Justice

iResearchNet




Criminal Justice > Criminology > Cyber Criminology > The Dark Web and Digital Crime

The Dark Web and Digital Crime




The Dark Web and Digital CrimeThe dark web and digital crime examines how the hidden layers of the internet — accessible only through anonymizing technologies such as the Tor network — function as infrastructure for a wide range of criminal activities extending beyond the drug marketplace focus that dominates popular discussion to encompass data trafficking, weapons sales, cybercrime services, child sexual exploitation, terrorist communications, and the provision of criminal tools and infrastructure that support offending across the surface web. Within Cyber Criminology, the dark web serves as both a distinct criminal environment with its own norms, governance structures, and market dynamics and as an enabling infrastructure layer that supports criminal operations conducted primarily on the surface web — a dual function that complicates both the analytical understanding and the law enforcement response to dark web-facilitated crime. While the article on Cybercrime and the Dark Web within this category examines marketplace ecosystems in depth, this article takes a broader perspective on the dark web’s role across the full spectrum of digital crime, examining its function as criminal infrastructure, its relationship to the broader cybercrime ecosystem, the evolving character of dark web criminal activity, the law enforcement strategies deployed against it, and the policy questions its persistence raises within the broader field of Criminology.

Introduction

The dark web’s significance for digital crime lies not in its size — dark web traffic constitutes a tiny fraction of total internet activity — but in the concentration of criminal activity it enables and the investigative challenges it creates. The anonymity provided by Tor and similar networks allows criminal actors to operate with a degree of protection from identification that the surface web, with its traceable IP addresses and registerable domains, does not provide. This anonymity enables the sustained operation of criminal marketplaces, forums, and services that would be rapidly identified and shut down on the surface web, creating persistent criminal infrastructure that supports both the direct commission of crime and the provision of tools and services used by criminals operating elsewhere (Moore & Rid, 2016; Jardine, 2015).

The relationship between the dark web and the surface web is more porous than popular imagery suggests. Many cybercriminals operate across both environments, using dark web forums and marketplaces for procurement and coordination while conducting their actual criminal operations — phishing campaigns, ransomware deployments, fraud schemes — against targets on the surface web. Stolen data exfiltrated through surface web breaches is sold on dark web marketplaces. Malware developed and distributed through dark web forums is deployed against surface web targets. Cryptocurrency laundered through dark web mixing services originated from ransomware payments and other surface web criminal operations. The dark web thus functions less as a separate criminal domain than as the backstage infrastructure of a cybercrime ecosystem that operates primarily on the surface web (Lusthaus, 2018; Holt, 2013).




The Dark Web as Criminal Infrastructure

Data Markets and Stolen Information

The trafficking of stolen data — credit card numbers, bank account credentials, personal identity information, corporate data, medical records, and login credentials — represents one of the dark web’s most economically significant criminal functions. Dark web marketplaces and specialized forums operate as wholesale and retail markets for data compromised through breaches, phishing campaigns, and malware infections, providing the supply chain that connects data theft to data exploitation (Hutchings & Holt, 2015). The commodification of stolen data has produced standardized pricing: a stolen credit card with full verification data typically sells for $10 to $50, a “fullz” package containing a complete identity profile commands $30 to $100, and corporate network access credentials may sell for hundreds or thousands of dollars depending on the target organization’s size and industry (Ablon, Libicki, & Golay, 2014).

The market infrastructure facilitates a division of labor that separates the individuals who steal data from those who exploit it. Initial access brokers specialize in compromising organizational networks and selling the resulting access to ransomware operators, corporate espionage actors, and other buyers. Credential dealers aggregate stolen login information from multiple breaches and sell curated collections organized by service, institution, or geographic region. Carding forums specialize in credit card fraud, providing not only stolen card data but also the tools (card-checking services, drop address networks, cashout techniques) necessary to monetize stolen financial instruments. This specialization mirrors legitimate market structures and creates efficiencies that increase the volume and profitability of data-driven crime (Leukfeldt, Lavorgna, & Kleemans, 2017).

The pricing dynamics of dark web data markets reveal the economic logic of the criminal data economy. Fresh data commands premium prices because it is more likely to be valid and unexploited. Data from financial institutions in wealthy countries commands higher prices than data from less affluent markets. Bulk purchases receive volume discounts. And the market responds to supply shocks: major data breaches that release large volumes of a particular data type depress prices as supply exceeds demand, while scarcity of data from particular institutions or regions elevates prices. These dynamics are consistent with the economic behavior of legitimate markets and support the analytical framework of cybercrime as an industry with its own supply-and-demand dynamics (Holt, 2013; Lusthaus, 2018).

Cybercrime-as-a-Service

The dark web hosts a mature cybercrime-as-a-service (CaaS) ecosystem in which specialized providers offer tools, infrastructure, and services that enable criminal operations by actors who may lack the technical capability to conduct those operations independently. Ransomware-as-a-service platforms provide ready-made ransomware variants, victim negotiation portals, and payment processing infrastructure to affiliates who conduct the actual attacks. DDoS-for-hire services (also known as “booter” or “stresser” services) sell access to botnet resources that can be directed against targets for a few dollars per hour. Phishing kits — pre-packaged phishing page templates, email distribution tools, and credential-harvesting infrastructure — enable individuals with minimal technical skill to conduct phishing campaigns that would previously have required significant expertise (Hutchings & Clayton, 2016; Holt & Bossler, 2016).

The CaaS model has fundamentally altered the threat landscape by decoupling criminal intent from criminal capability. An individual motivated to conduct a ransomware attack no longer needs to develop ransomware, build network infrastructure, or establish cryptocurrency laundering channels — all of these capabilities can be rented or purchased from specialized dark web providers. The result is a dramatic expansion of the potential attacker population and a corresponding increase in the volume and diversity of cybercrime operations. The policy implication is that enforcement strategies targeting individual criminal actors address only the demand side of the CaaS ecosystem; reducing the overall volume of crime requires disrupting the supply side — the platforms, services, and infrastructure that enable criminal operations at scale (Leukfeldt et al., 2017).

Dark Web Criminal Activity Beyond Marketplaces

Child Sexual Exploitation

The dark web hosts dedicated platforms for the distribution of child sexual abuse material (CSAM) that exploit anonymity to evade the detection mechanisms deployed on the surface web. Dark web CSAM forums and file-sharing services operate through invitation-only access, contribution requirements (requiring members to upload novel CSAM as a condition of membership), and operational security measures that combine Tor anonymity with encryption, cryptocurrency payment, and counter-forensic practices designed to resist law enforcement identification. The scale of dark web CSAM distribution is substantial: the Welcome to Video marketplace, seized in 2019, contained over 250,000 videos and had been accessed by over one million unique cryptocurrency addresses worldwide (U.S. Department of Justice, 2019).

The dark web’s role in child exploitation extends beyond material distribution to encompass live-streaming abuse, grooming facilitation, and the coordination of offender networks. The anonymity that the dark web provides enables the formation of communities in which the normalization of child sexual abuse occurs through peer reinforcement — members share material, discuss offending behavior, and develop ideological frameworks that rationalize their conduct. The social dynamics of these communities may contribute to the escalation of offending, as community norms that celebrate the production of increasingly severe material create incentive structures that drive escalation among producers seeking community status (Quayle & Taylor, 2003; Kloess, Beech, & Harkins, 2014).

Weapons, Fraud, and Miscellaneous Criminal Services

Dark web marketplaces list weapons (primarily firearms and ammunition), counterfeit currency, fraudulent identity documents, and a range of criminal services including hacking-for-hire, surveillance services, and — controversially — alleged assassination services. The actual volume of weapons transactions on the dark web is substantially smaller than drug and data transactions: Europol and RAND Corporation research has documented that weapons represent a small fraction of dark web marketplace revenue, and many purported weapons vendors are scammers who take payment without delivering products (Kruithof et al., 2016). The operational significance of dark web weapons sales for violent crime in the United States remains unclear, as the domestic firearms market provides substantially easier legal and illegal acquisition pathways than dark web purchasing for most buyers.

Fraud-related services available on the dark web include counterfeit document production (passports, driver’s licenses, social security cards), tax refund fraud kits, unemployment insurance fraud toolkits, and tutorial materials that teach fraud techniques to aspiring offenders. The availability of fraud toolkits and educational materials on the dark web creates a pathway into criminal activity for individuals who might not independently develop the techniques necessary for financial crime — a supply-side contribution to fraud volume that parallels the CaaS dynamic in cybercrime more broadly. The sale of SIM swapping services, bank account drop services, and money mule recruitment through dark web channels illustrates the integration of dark web services into criminal operations that ultimately affect victims on the surface web (Hutchings & Holt, 2015).

Law Enforcement and the Resilience Problem

Investigative Approaches

Law enforcement agencies have developed specialized capabilities for investigating dark web criminal activity, combining technical deanonymization techniques, undercover operations, cryptocurrency analysis, and traditional investigative methods. The FBI, HSI, DEA, Postal Inspection Service, and their international counterparts maintain units with expertise in dark web investigation, and major operations against dark web criminal platforms have demonstrated significant operational capability. The seizure of Silk Road (2013), the coordinated takedown of AlphaBay and covert operation of Hansa (2017), the disruption of Welcome to Video (2019), and the international Operation SpecTor (2023) represent landmark law enforcement achievements that have dismantled major criminal platforms, identified thousands of users, and generated intelligence that fuels ongoing investigations (Décary-Hétu & Giommoni, 2017).

Technical deanonymization — defeating the anonymity protections that Tor provides — remains the most challenging dimension of dark web investigation. Methods that have been employed include the exploitation of browser vulnerabilities (Network Investigative Techniques that reveal users’ real IP addresses), the deployment of traffic analysis at Tor network entry and exit points, the exploitation of operational security failures by marketplace administrators, and the analysis of cryptocurrency transaction patterns that link dark web transactions to real-world identities through exchange records and behavioral analysis. Each of these methods has limitations: browser exploits depend on the discovery of usable vulnerabilities, traffic analysis requires favorable network positioning, OPSEC failures are unpredictable, and cryptocurrency analysis becomes less effective as privacy-enhancing technologies improve (Chainalysis, 2024).

The covert takeover of criminal platforms — in which law enforcement agencies secretly assume control of dark web marketplaces and operate them to gather intelligence on users — represents the most operationally sophisticated investigation technique. The Dutch National Police’s month-long covert operation of the Hansa marketplace in 2017, during which investigators modified the platform to capture user data including shipping addresses, cryptocurrency transactions, and plaintext passwords, generated thousands of investigative leads that resulted in arrests across multiple countries. The technique’s effectiveness is counterbalanced by the legal and ethical controversies it generates — the government’s continued operation of a platform that distributes illegal drugs and other contraband raises questions about the proportionality of the investigative benefit relative to the harm that the platform’s continued operation enables (Europol, 2017).

The Whack-a-Mole Dynamic

The fundamental challenge of law enforcement’s dark web strategy is the resilience of the criminal ecosystem to disruption. Marketplace takedowns produce temporary disruptions — transaction volumes decline for weeks to months as users regroup — but the market recovers as activity migrates to surviving platforms, new platforms emerge to fill the void, and the criminal demand that the taken-down marketplace served finds alternative supply channels. Décary-Hétu and Giommoni (2017) documented this recovery pattern across multiple takedown events, finding that the aggregate volume of dark web commerce remained relatively stable despite successive law enforcement operations targeting major platforms.

The resilience of the dark web criminal ecosystem reflects its distributed, market-based organizational structure. Because no single entity controls the ecosystem, the removal of individual components — a marketplace, a vendor, a hosting provider — does not disable the system. Criminal entrepreneurs create new platforms to replace those that are seized, vendors migrate their operations to surviving marketplaces or establish independent vendor shops, and the underlying infrastructure of Tor anonymity and cryptocurrency payment remains available to support new criminal ventures. The dynamic is analogous to the “balloon effect” documented in drug enforcement research, in which the suppression of supply in one location displaces it to another rather than reducing it in aggregate (Décary-Hétu & Giommoni, 2017; Soska & Christin, 2015).

The cumulative impact of sustained disruption operations — rather than the effect of any single takedown — represents the most plausible mechanism through which law enforcement can constrain dark web criminal activity. Repeated disruptions impose costs on participants (lost funds, lost reputation, increased risk), degrade trust within the ecosystem (uncertainty about whether platforms or fellow users are law enforcement), and consume criminal resources that must be devoted to reconstruction rather than operation. Whether the cumulative costs of disruption exceed the criminal revenues that the ecosystem generates — whether, in other words, sustained enforcement pressure can produce a net reduction in dark web crime rather than merely a redistribution of criminal effort — remains an empirical question whose answer depends on the scale and persistence of enforcement investment.

Policy Implications and Future Trajectory

The Anonymity Dilemma

The dark web presents a governance dilemma that admits no clean resolution: the same anonymity technology that enables criminal activity also serves essential privacy, press freedom, and human rights functions. Tor is used by journalists to communicate with sources in authoritarian regimes, by domestic violence survivors to access support services without being tracked by abusers, by political dissidents to organize and communicate without state surveillance, and by ordinary citizens who value browsing privacy. Any policy measure that degrades the anonymity of the Tor network — technical attacks, mandatory backdoors, regulatory restrictions — would affect these legitimate users alongside criminal ones (Jardine, 2015; Tor Project, 2024).

The policy response has appropriately focused on targeting criminal users of the dark web rather than attempting to eliminate the anonymity infrastructure itself. Law enforcement operations against dark web platforms, vendors, and users impose costs on criminal activity without degrading the technology’s protective functions for legitimate users. The development of improved investigation techniques — cryptocurrency analysis, traffic analysis, undercover capability — expands law enforcement’s ability to penetrate criminal anonymity while leaving the anonymity protections available to non-criminal users intact. This targeted approach is not perfectly effective — many criminal actors remain anonymous despite law enforcement efforts — but it respects the dual-use character of anonymity technology in a way that blanket restrictions would not.

Technological Evolution and Adaptation

The dark web’s future trajectory will be shaped by the ongoing competition between anonymity-enhancing technologies and law enforcement capabilities. The development of decentralized marketplace protocols that eliminate the centralized administrator whose compromise or arrest can disable a platform, the increasing adoption of privacy-focused cryptocurrencies that resist analytical tracing, and the application of AI to automate criminal operations and enhance operational security all suggest that the technical challenges of dark web investigation will continue to increase. Simultaneously, advances in blockchain analysis, AI-enhanced traffic analysis, and international cooperation frameworks are expanding law enforcement capabilities.

The emergence of encrypted messaging platforms as alternative venues for criminal coordination — partially displacing the dedicated dark web platforms that have been the primary targets of law enforcement operations — illustrates the adaptive character of criminal ecosystems. If enforcement pressure makes dark web marketplaces increasingly risky, criminal activity may migrate to Telegram channels, encrypted group chats, and other communication environments that provide comparable operational security without the technical complexity and reputational risk associated with dedicated dark web platforms. This migration dynamic ensures that effective policy responses must address the full spectrum of anonymous and encrypted criminal communication rather than focusing exclusively on the Tor-accessible dark web.

Conclusion

The dark web functions as the infrastructure layer of the cybercrime ecosystem — providing the anonymous communication channels, marketplace platforms, and criminal services that support offending across the full spectrum of digital crime. Its significance lies not in the volume of activity it hosts, which is modest relative to the surface web, but in the concentration of criminal activity it enables and the investigative challenges its anonymity protections create. Law enforcement has developed significant operational capability against dark web criminal platforms, achieving notable takedowns and generating intelligence that fuels ongoing prosecution. But the resilience of the dark web criminal ecosystem — its capacity to regenerate after disruption, to adapt to enforcement pressure, and to evolve alongside the technologies that sustain it — ensures that the dark web will remain a persistent feature of the criminal landscape and a continuing challenge for criminal justice institutions.

References

  1. Ablon, L., Libicki, M. C., & Golay, A. A. (2014). Markets for cybercrime tools and stolen data: Hackers’ bazaar. RAND Corporation. https://doi.org/10.7249/RR610
  2. Aldridge, J., & Décary-Hétu, D. (2016). Hidden wholesale: The drug diffusing capacity of online drug cryptomarkets. International Journal of Drug Policy, 35, 7–15. https://doi.org/10.1016/j.drugpo.2016.04.020
  3. Chainalysis. (2024). The 2024 crypto crime report. https://www.chainalysis.com/blog/crypto-crime-2024/
  4. Christin, N. (2013). Traveling the Silk Road: A measurement analysis of a large anonymous online marketplace. Proceedings of the 22nd International Conference on World Wide Web (pp. 213–224). https://doi.org/10.1145/2488388.2488408
  5. Décary-Hétu, D., & Giommoni, L. (2017). Do police crackdowns disrupt drug cryptomarkets? Crime, Law and Social Change, 67(1), 55–75. https://doi.org/10.1007/s10611-016-9644-4
  6. Europol. (2017). Massive blow to criminal dark web activities after globally coordinated operation. Press release.
  7. Europol. (2024). Internet Organised Crime Threat Assessment (IOCTA) 2024. European Union Agency for Law Enforcement Cooperation.
  8. Holt, T. J. (2013). Examining the forces shaping cybercrime markets online. Social Science Computer Review, 31(2), 165–177. https://doi.org/10.1177/0894439312452998
  9. Holt, T. J., & Bossler, A. M. (2016). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
  10. Hutchings, A., & Clayton, R. (2016). Exploring the provision of online booter services. Deviant Behavior, 37(10), 1163–1178. https://doi.org/10.1080/01639625.2016.1169829
  11. Hutchings, A., & Holt, T. J. (2015). A crime script analysis of the online stolen data market. British Journal of Criminology, 55(3), 596–614. https://doi.org/10.1093/bjc/azu106
  12. Jardine, E. (2015). The dark web dilemma: Tor, anonymity and online policing. Global Commission on Internet Governance Paper Series, No. 21.
  13. Kloess, J. A., Beech, A. R., & Harkins, L. (2014). Online child sexual exploitation. Trauma, Violence, & Abuse, 15(2), 126–139. https://doi.org/10.1177/1524838013511543
  14. Kruithof, K., Aldridge, J., Décary-Hétu, D., Sim, M., Dujso, E., & Hoorens, S. (2016). Internet-facilitated drugs trade. RAND Corporation. https://doi.org/10.7249/RR1607
  15. Leukfeldt, R., Lavorgna, A., & Kleemans, E. R. (2017). Origin, growth, and criminal capabilities of cybercriminal networks. Crime, Law and Social Change, 67(2), 145–164. https://doi.org/10.1007/s10611-016-9663-1
  16. Lusthaus, J. (2018). Industry of anonymity: Inside the business of cybercrime. Harvard University Press.
  17. Martin, J. (2014). Drugs on the dark net. Palgrave Macmillan.
  18. Moore, D., & Rid, T. (2016). Cryptopolitik and the darknet. Survival, 58(1), 7–38. https://doi.org/10.1080/00396338.2016.1142085
  19. Quayle, E., & Taylor, M. (2003). Model of problematic internet use in people with a sexual interest in children. CyberPsychology & Behavior, 6(1), 93–106. https://doi.org/10.1089/109493103321168009
  20. Soska, K., & Christin, N. (2015). Measuring the longitudinal evolution of the online anonymous marketplace ecosystem. Proceedings of the 24th USENIX Security Symposium (pp. 33–48).
  21. Tor Project. (2024). Tor: Overview. https://www.torproject.org/about/overview.html
  22. U.S. Department of Justice. (2019). South Korean national and hundreds of others charged worldwide in the takedown of the largest darknet child pornography website. Press release.
  23. Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
  24. Yar, M., & Steinmetz, K. F. (2019). Cybercrime and society (3rd ed.). SAGE Publications.

Related Articles

  • Cybercrime and the Dark Web
  • Cryptocurrency and Crime
  • Cybercrime and Organized Crime
  • Online Drug Markets
  • Cybercrime Investigation and Digital Forensics




Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube
  • Criminology
    • Clinical Criminology
    • Comparative Criminology
    • Crime as a Social Phenomenon
    • Crime in Criminology
    • Criminology and Criminal Justice Careers
    • Criminology and Criminal Justice Degrees
    • Criminology and Criminal Justice Education
    • Criminology and Public Policy
    • Criminology as Social Science
    • Cyber Criminology
      • Algorithmic Bias in Criminal Justice
      • Artificial Intelligence and Crime
      • Big Data and Criminal Justice
      • Body-Worn Cameras and Policing
      • Child Sexual Exploitation Online
      • Corporate Cybercrime and Data Breaches
      • Crime in the Digital Age
      • Cryptocurrency and Crime
      • Cyberbullying in America
      • Cybercrime and Organized Crime
      • Cybercrime and the Dark Web
      • Cybercrime Investigation and Digital Forensics
      • Cybercrime Offenders and Motivations
      • Cybercrime Prevention and Digital Literacy
      • Cybercrime Reporting and Statistics in America
      • Cybercrime Typologies
      • Cybercrime Victimization
      • Cyberstalking and Online Harassment
      • Cyberterrorism and National Security
      • Digital Criminology and Public Policy
      • Digital Divide and Crime
      • Digital Evidence in American Courts
      • Digital Society and Crime
      • Digital Surveillance and Crime Control
      • Digital Vigilantism in America
      • Emerging Cybercrime Threats
      • Facial Recognition and Law Enforcement
      • Federal Cybercrime Law in America
      • Hacking and Unauthorized Access
      • Identity Theft in America
      • International Cybercrime Cooperation
      • Malware and Ransomware Attacks
      • Nation-State Cyberattacks and U.S. Security
      • Online Drug Markets
      • Online Fraud and Financial Cybercrime
      • Online Radicalization and Extremism
      • Phishing and Social Engineering
      • Platform Accountability and Online Harm
      • Privacy, Civil Liberties, and Digital Crime Control
      • Sextortion and Image-Based Abuse
      • Social Media and Criminal Behavior
      • The Dark Web and Digital Crime
    • History of Criminology
    • Psychology and Criminology
    • Sociology and Criminology
    • Urban Criminology