SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Leaked credentials and lookalike domains join Ontinue's ION MXDR analyst queue
Ontinue launched ION for Dark Web Monitoring, an ION MXDR add-on that routes leaked credentials and lookalike domains to its analysts. Findings land in Microsoft Sentinel beside each customer's other alerts and are worked by the same analysts.
The Watch · Security desk
What happened
- Credential monitoring covers logins tied to customer domains that turn up in breaches, criminal marketplaces or other external sources.
- Typosquatting detection flags domains built to mimic a customer's brand and assesses how risky each one is.
- Approved response actions run automatically or with customer oversight, depending on rules of engagement agreed in advance.
- Ontinue's release says only 19% of organizations continuously monitor for credential exposure and remediate it automatically.
Why it matters
- decision Teams already paying a threat-intel vendor for leak alerts now have to decide whether this add-on replaces that feed or duplicates it.
- constraint Exposures get closed only as far as the agreed rules of engagement let Ontinue's analysts act. Where they cannot touch an account, the reset still falls to the customer's own staff.
- capability A leaked login sitting in Sentinel can be checked against other alerts on the same account in one console, without a separate intel portal.
The threat here needs no exploit. Ontinue's release describes compromised credentials traded across criminal forums and lookalike domains created to impersonate trusted brands [16]. I think finding a leaked password is the cheaper part of the job. The expensive part is getting it changed before whoever bought it logs in, and the release says exposed credentials can show up on the dark web within 24 hours [13].
Ontinue says its analysts handle the expensive part. "Most dark web monitoring solutions stop at detection," said Moritz Mann, CEO of Ontinue. "ION for Dark Web Monitoring goes further by investigating findings, assessing risk, and helping customers take action before exposures become incidents." [8] Findings go through the ION SecOps Platform to the same Cyber Defense Center analysts and automation workflows that already cover customer environments around the clock [3]. They are worked with the processes behind what Ontinue calls its Agentic SOC [11].
The release attributes its 19% figure only to "reports" [14]. It puts the gap down to staffing: many organizations receive threat intelligence feeds and dark web alerts but lack the resources to investigate them, judge relevance or coordinate a response [15].
By that account the add-on sells triage labour. The one customer quoted describes it as an addition to what Epiq already runs. "ION for Dark Web Monitoring expands our visibility beyond our existing tools, giving us better insight into external risks and bringing validated findings into the managed security operations we already trust," said Jason Burzenski, Vice President, Global Head of Cyber Security at Epiq [9][10].
The release calls its intelligence sources curated and trusted, and says they cover the clear, deep and dark web [2]. It does not name them, list which response actions apply to a leaked account, or give a price [12].
What to watch
- Time-to-remediate figures from Ontinue for leaked-credential findings, the measure of whether managed triage closes exposures faster than a raw alert feed.
- Customers saying whether they dropped a standalone dark web monitoring subscription after adopting the add-on.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence25
- Adoption10
- Hype gap+35
- Incentives85
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ontinue announced ION for Dark Web Monitoring (DWM), a managed add-on service that extends ION MXDR to identify exposed credentials, detect brand impersonation attempts and uncover emerging external threats.
- [2]
ION for Dark Web Monitoring monitors customer-owned domains and brand assets across intelligence sources the release calls curated and trusted, spanning the clear, deep and dark web.
- [3]
Findings are validated, enriched and operationalized through the ION SecOps Platform, using the same Cyber Defense Center analysts, automation workflows and response capabilities already protecting customer environments 24/7.
- [4]
Approved response actions can be executed automatically or with customer oversight based on predefined rules of engagement.
- [5]
External exposures flow directly into Microsoft Sentinel and the ION SecOps Platform, where they are investigated alongside other security signals.
- [6]
The service continuously identifies credentials associated with customer domains that may have been exposed through breaches, criminal marketplaces or other external sources.
- [7]
The service detects suspicious domains designed to mimic trusted brands (typosquatting and brand impersonation) and assesses their potential risk.
- [8]
"Most dark web monitoring solutions stop at detection. ION for Dark Web Monitoring goes further by investigating findings, assessing risk, and helping customers take action before exposures become incidents."
- [9]
"ION for Dark Web Monitoring expands our visibility beyond our existing tools, giving us better insight into external risks and bringing validated findings into the managed security operations we already trust."
- [10]
Jason Burzenski is Vice President, Global Head of Cyber Security at Epiq.
- [11]
Exposures are investigated using the same automation, detection and response processes that support Ontinue's Agentic SOC.
- [12]
The published announcement does not name the intelligence sources, list the specific response actions for a leaked account, or state a price.
- [13]
The release states that exposed credentials can show up on the dark web within 24 hours.
- [14]
The release states that 'reports have shown' only 19% of organizations continuously monitor for credential exposure and automatically remediate it; it does not name the reports.
- [15]
According to the release, many organizations receive threat intelligence feeds and dark web monitoring alerts but lack the resources to investigate findings, determine relevance or coordinate response actions.
- [16]
The release says compromised credentials are traded across criminal forums and lookalike domains are created to impersonate trusted brands.
Sources
1 independent publisher whose own reporting we read for this story.
- helpnetsecurity.comOntinue extends ION MXDR with managed dark web monitoring
1 article · October 6, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Managed Detection and ResponseFollow
- Brand ImpersonationFollow
- Dark web monitoringFollow
Entities
- OntinueFollow
- ION MXDRFollow
- Microsoft SentinelFollow
- EpiqFollow
- International Data Corp.Follow
- Moritz MannFollow
- Jason BurzenskiFollow