Taking on the Dark Web: Law Enforcement Experts ID Investigative Needs (2024)

The “dark web” is an internet shadow world where the good and the bad co-exist. On the good side, the dark web provides anonymous, highly secure communication channels to shield classified government activity and protect reform agents such as human rights activists and journalists opposed by oppressive foreign regimes. On the bad side, the dark web has emerged as an important hub of criminal commerce, a fully functional marketplace where hidden customers can buy from hidden sellers with relative confidence, often with customer ratings available, just as on the public-facing web.

The anonymity of illicit activity on the dark web cloaks an enterprise of mounting concern to authorities. One site alone generated an estimated $219 million in annual revenue as of 2017, according to a new NIJ-supported report by the RAND Corporation (RAND). The report, “Identifying Law Enforcement Needs for Conducting Criminal Investigations Involving Evidence on the Dark Web,” explores better ways to investigate dark web crimes. Although the dark web still accounts for just a fraction of all illicit sales online, it appears poised for rapid growth, according to the report.

The criminal side of the dark web relies on anonymizing technology and cryptocurrency to hide its trade in an assortment of contraband such as opioids and other drugs, bomb parts, weapons large and small, child p*rnography, social security numbers, body parts — even criminal acts for hire.

The dark web’s anonymity not only encourages illegal activities, it keeps many law enforcement agencies largely unaware of its existence, even while their jurisdictions are impacted by online transactional crimes.

To raise the visibility of the dark web among law enforcement agencies and identify tools that can help them police it, an NIJ-supported gathering of experts identified law enforcement’s key dark web challenges and opportunities, as well as high-priority needs for addressing them. The group included experts from federal, state, and local agencies; academic researchers; and civil rights advocates. Organized on behalf of NIJ by RAND and the Police Executive Research Forum, the experts’ workshop yielded high-level recommendations focused on the following:

  • Training — training officers and investigators to spot relevant dark web evidence.
  • Information-Sharing — improving information-sharing among agencies, both domestically and internationally.
  • New Structures for Cooperation — examining the benefits of building cross-organization structures for cooperation.
  • New Forensic Standards — developing new standards for forensic tools to collect dark web evidence on computers.
  • New Laws for Package Inspection — researching ways to modernize laws facilitating inspection of packages shipped by mail or other services.
  • Research on Crime Connections — researching the increasingly connected nature of crime to help law enforcement recognize and address both highly visible traditional crime and the less-visible crime on the dark web.

In all, the experts’ workshop identified 40 problems or opportunities and 46 potential solutions or needs related to dark web investigations. Nineteen needs were deemed high-priority, across four general subject areas: training, organizational cooperation and information-sharing, tool development, and other problems and opportunities. “Taken together,” said the RAND report on the workshop and its results, “the high-priority needs identified during the workshop represent a way to prepare law enforcement at all levels to better address the challenge posed by cybercrime, now and into the future.”

A key problem for law enforcement spotlighted by the workshop experts is a lack of knowledge of how the dark web operates and how criminals have begun to use it, the report said. See “A Snapshot of How the Dark Web Works.”

The Workshop Design and Objectives

The workshop participants prioritized needs using a formula that took into account both the perceived importance of a particular need and the perceived likelihood of meeting that need successfully. Thus, if two needs were rated of highest importance, one would be assigned a higher priority than the other if a law enforcement commitment to fulfilling that need had a perceived higher likelihood of success than committing to the second need.

The workshop covered six overarching topics. Those topics, and key established needs and challenges related to each, follow.

General Needs and Challenges

Rapid Changes in Volume of Use — Law enforcement sees evidence of a steady expansion of dark web activities but largely lacks quantitative data to inform effective responses and solutions to dark web activities.

Globalization — Dark web activity crosses local and state boundaries and national borders. The cross-jurisdictional nature of the dark web makes it essential that investigators collaborate across agencies. If agencies avoid the dark web because of its cross-jurisdictional nature, participants noted, “dark web actors might be emboldened by the lack of enforcement to conduct more illicit business using the dark web.”

The Need to Demystify the Dark Web – Some law enforcement participants expressed concern about exposing themselves and their departments to retaliation by malicious web users, should they act against dark web interests. The report, noting “a need to demystify the dark web” for law enforcement, stated, “Given the lack of definitive quantitative data, law enforcement is expected to act without comprehensive information regarding what works and what is needed to address these dark web challenges. Participants suggested police trainers could emphasize the commonalities of dark web investigations and traditional investigations, or “plain old police work.”

Command Buy-In for Additional Training — Participants noted a need to persuade law enforcement command staff to initiate dark web training and investigations. Command buy-in may be essential to commitments of funding and training time.

Training — Participants identified a need for two distinct categories of training:

  1. For line officers, courses to develop basic familiarity with digital evidence found at the scene.
  2. For specialized units, targeted training on evidence preservation as well as advanced training on methods used by criminals on the dark web.

Participants identified a need for more subject matter experts to conduct training. In all, the workshop participants identified 12 highest priority needs related to training, more than any other area.

Technical Needs and Challenges

Even as the anonymity of the dark web often keeps law enforcement at bay, basic tools can enable anyone to engage dark web services without much difficulty: “Basic internet literacy, a computer, and access to the internet is enough for any sufficiently motivated individual to begin supplying or purchasing illicit goods on the dark web,” the RAND report said. Law enforcement seizures can compromise entire markets, with buyers’ and sellers’ information de-anonymized. But users have found additional tools to protect their information.

A major challenge is interdicting dark web shipments through postal systems. The U.S. Postal Service alone is estimated to move more than 500 million parcels daily. In addition to the quantity of parcels, seizures from the Postal Service often require warrants.

As a high-priority need, the workshop experts called for conducting research into gaps in laws related to searching packages.

Crime Identification

Line officers need to develop awareness of the types and scope of illicit dealings on the dark web. Participants pointed to the potential of new state task forces, which could share data, across organizations and jurisdictions, on the dark web.

Privacy Protection

Workshop participants related a need for guidance from federal partners on how to manage privacy concerns during investigations. Although not identified as a top priority, participants also identified a need for research to understand how much privacy citizens would sacrifice in order to gain security.

Suspect Identifications

Participants noted that officers responding to criminal activity need to develop the ability to recognize items, such as login information, that could help link suspects to dark web sites, the report said.

Evidence Identification, Access, and Preservation

Law enforcement faces a challenge both in acquiring relevant technical data and in turning it into evidence understandable to the public, members of which sit on juries deciding the guilt or innocence of those charged with dark web crimes. The evidence challenge is heightened by the growth of data quantity, indecipherable formats, and the need for cross-jurisdictional coordination. In light of difficulties posed by the encryption and anonymity features of software used on the dark web, the participants urged that law enforcement use best available standards, tools, and processes to capture evidence. To that end, a high-priority need identified during the workshop is encouraging establishment of standards for new processes used to capture dark web evidence.

Resource Allocation — Several participants noted that it could be beneficial to pool resources in new task forces.

Adaptation and Fluctuation — Successful law enforcement operations against dark web interests commonly cause users to adapt quickly, shifting to different markets or creating entirely new markets. Workshop participants noted that dark web users often exchange information on how to evade detection by law enforcement.

Legal Needs and Challenges

The Multijurisdictional Nature of Crime — Authorities are challenged by web-based crime involving different jurisdictions with a multitude of relevant laws. Participants emphasized the importance of multiagency partnerships in that regard.

Entrapment — Concerns were expressed over the possibility of legal actions for entrapment brought by web users conducting business on dark web marketplaces created by law enforcement, the report said. The risk can arise when authorities must impersonate criminals to establish trust with criminals on the dark web.

Conclusion

Law enforcement authorities identified priority needs for investigating criminal activity on the dark web:

  • Raising awareness of the dark web among state and local authorities.
  • Forging cross-jurisdictional partnerships among agencies.
  • Initiating more and better training to equip officers to identify dark web evidence and activity.
  • Equipping special investigation units with advanced knowledge of dark web methods and activities. Because of the clandestine nature of the dark web, many state and local law enforcement agencies are generally unaware of its existence and its capacity for engendering crime in their jurisdictions.

Sidebar: A Snapshot of How the Dark Web Works

The dark web is a portion of the “dark net,” a segment of the internet employing encryption and anonymizing technology designed to prevent tracking.

For purposes of the workshop, the dark web was defined as those hyperlinked services on the dark net accessible only through The Onion Router (or Tor) protocol or similar protocols. Tor is a specially configured browser enabling users to access services on the web in ways that are difficult or impossible to trace. Typical web browsers reveal their unique IP (Internet Protocol) address, making them traceable by law enforcement. But a dark web browser issues a false IP address, using a series of relays, to mask the user’s identity.

A significant portion of dark web activity is lawful. The Tor browser itself was initially developed by the U.S. Naval Research Laboratory in the 1990s and released to the public in 2002. Tor’s original purpose, the RAND report noted, was “to conceal the identities of American operatives or dissidents attempting to communicate within oppressive regimes.” The anonymizing browser is also used by some journalists working internationally, the report said.

The fact that the dark web is highly anonymized and encrypted, however, also attracts illicit conduct. One study[1] estimated that 57 percent of dark websites facilitate illicit activity, according to the RAND report. At various points in 2013 and 2016, large drug sales on the dark net approached a quarter of all cryptomarket drug revenue, the report said. But researchers found most drug sales on the dark web were under $100.

Overall, illicit internet use is on the rise. Workshop participants reported a sharp increase in crime brought to their attention with a dark web element, and according to one reported study[2], total monetary losses from internet-enabled crime was estimated at more than $1.4 billion in 2016. At a Police Executive Research Forum (PERF) conference in 2018, DEA agents noted a significant increase in narcotics cases involving the dark web, and FBI officials reported a surge in use of the dark web to purchase malware and launder money, the dark web workshop report said.

Fentanyl sales on the dark web have been a major focus of U.S. law enforcement. Other potential illegal activities include identity theft, blueprint distribution, human trafficking, and weapon sales. For authorities, the dark web has been elusive but not invulnerable. The FBI’s 2013 crackdown on the Silk Road marketplace, an online narcotics bazaar, was a high-profile response to a large operation, the report noted. More recently, a collaboration of the FBI, DEA, ICE, and Homeland Security Investigations has shut down two major dark web markets, AlphaBay and Hansa, the RAND report noted. In January 2018, the Department of Justice created a joint enforcement team focused on dark web opioid sales. State and local agencies have also engaged in collaborative dark web enforcement initiatives, the report said.

About This Article

The research described in this article was funded by NIJ grant 2013-MU-CX-K003, awarded to the RAND Corporation. This article is based on the grantee final report, “Identifying Law Enforcement Needs for Conducting Criminal Investigations Involving Evidence on the Dark Web” (2019), by Sean E. Goodison, Dulani Woods, Jeremy D. Barnum, Adam R. Kemerer, and Brian A. Jackson. The workshop activities underlying the report were supported by RAND in partnership with PERF, on behalf of NIJ. The program is part of the Priority Criminal Justice Needs Initiative of NIJ in partnership with RAND, PERF, RTI International, and the University of Denver.

Taking on the Dark Web: Law Enforcement Experts ID Investigative Needs (2024)

FAQs

What is the dark web investigation? ›

Dark Web Investigation is a service which monitors available Internet resources that are associated with cybercrime. Dark Web Investigation allows you to search for information on the darknet that relates to an organization or its web service customers.

What is the most common crime on the dark web? ›

The Dark Web is associated with a whole host of crimes, and some of the most common crimes are white collar crimes like money laundering, identity theft and fraud.

What can law enforcement agencies do to enhance their investigative capabilities? ›

Training in research-based investigative procedures and access to tools and resources can help law enforcement officers carry out successful investigations.

What are the illegal activities on the dark web? ›

These include the buying and selling of illegal drugs, weapons, passwords, and stolen identities, as well as the trading of illegal p*rnography and other potentially harmful materials.

What private information is on the dark web? ›

Darknets use complex, layered encryption systems to keep their users' identities and locations anonymous. Exploiting this capability, Dark Web users communicate and share data confidentially, without being tracked by private companies or public organizations, including the government and law enforcement.

How to check dark web report google? ›

To start, open Google One, go to “Dark web report,” and tap Set Up > Start Monitoring. You'll then be able to choose exactly what information you'd like to keep an eye on, including your name, address, email, password, and phone number.

How to monitor the dark web? ›

You can set up a monitoring profile with a paid Google One membership. Sign up for Google One. You don't need a paid Google One membership to run a dark web report for the email address associated with your Google Account. Scan the dark web for your email address.

How common is it to have your information on the dark web? ›

Identity… While the thought of having your personal information on the dark web can be terrifying for some, the truth is, if you have been using the internet or any popular online services for some time now, the likelihood that your personal information is already on the dark web is actually pretty high.

Which is the number 1 most common Internet crime? ›

Most reported cyber crime in the U.S. 2023, by number of individuals affected. In 2023, the most common type of cyber crime reported to the United States internet Crime Complaint Center was phishing and spoofing, affecting approximately 298 thousand individuals.

What are investigative techniques in law enforcement? ›

Some tools that police use when investigating a crime are interviews and interrogations. Police will also collect any physical evidence left at the scene of the crime and evidence referred to in an interview or interrogation. They then use the information and evidence to piece together a police report of the crime.

What do law enforcement investigators do? ›

They conduct interviews, examine records, monitor suspects, and participate in raids and arrests. Detectives typically investigate serious crimes, such as assaults, robberies, and homicides.

What software do police use? ›

Computer-aided dispatch (CAD) is police software that helps first responders receive dispatch calls, direct resources to appropriate areas and record incidents from the initial 911 call to the resolution of the incident.

How much crime happens on the dark web? ›

Highlights: Dark Web Crime Statistics

87% of dark web listings are related to some form of criminal activity. In 2019, the dark web saw a 44% growth in the number of marketplaces. 60% of darknet vendors offer stolen financial credentials for sale.

What is the activity on the dark web? ›

The dark web pulls up sites using information that isn't indexed online, such as bank accounts, email accounts, and databases. It also has a reputation for being associated with illicit and unethical activities.

What is illegal on web? ›

Anything that is illegal offline is also illegal on the internet, including fraud, theft, gambling, drug trafficking, prostitution, and child p*rnography. Certain internet crimes, however, may only be committed online, and some people do not even realize they're engaging in illegal behavior.

What does the dark web do with your information? ›

Scams and fraud: Criminals tend to frequent the dark web, and if you aren't careful, you might get scammed out of money or blackmailed. Data leaks: The dark web isn't as private as you might think, and other users might leak your personally identifiable information after a data breach or steal your identity.

What is the dark web and is it a threat? ›

The dark web is a part of the internet that is only accessible with a special browser. It has legitimate uses, but abuse by malicious actors is a cybersecurity problem. A web search for “dark web” and “ransomware” turns up a wealth of news about ransomware gangs selling and threatening to sell stolen information.

What is dark web hunting? ›

How does Dark Web Hunting work? Our hunters search for threat actor chatter in social media, surface, and deep and dark web forums. They proactively scan for, investigate, and analyze terrorist, hacktivist, and criminal activity conducted against you or your industry from outside your network.

How much of the internet is the dark web? ›

The dark web is only a small fraction (0.01%) of the deep web, which contains Internet content that is not searchable by your standard search engines. In other words, if Google can't find what you're looking for, it's probably still out there in the World Wide Web; it's just in the harder-to-access deep web.

Top Articles
Latest Posts
Article information

Author: Roderick King

Last Updated:

Views: 6255

Rating: 4 / 5 (51 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Roderick King

Birthday: 1997-10-09

Address: 3782 Madge Knoll, East Dudley, MA 63913

Phone: +2521695290067

Job: Customer Sales Coordinator

Hobby: Gunsmithing, Embroidery, Parkour, Kitesurfing, Rock climbing, Sand art, Beekeeping

Introduction: My name is Roderick King, I am a cute, splendid, excited, perfect, gentle, funny, vivacious person who loves writing and wants to share my knowledge and understanding with you.