HEROIC DarkWatch · Law N°21.663 · Dark Web Monitoring

Your organization's credentials may be exposed right now.

81% of security breaches occur because attackers use stolen credentials from employees. Cynersis detects which accounts from your domain are compromised on the dark web before they are used.

Dark Web MonitoringCompromised credentialsReal-time alertsLaw N°21.663OIV / ANCI
The silent threat

An employee uses the same password at work and in an external service that suffers a breach.

That credential gets published on dark web forums. An attacker buys it, tests access to your VPN or corporate email, and enters without raising alarms — because they are using legitimate credentials. Your antivirus and firewall detect nothing.

What organizations are affected?

Any organization with employees who have corporate email accounts — regardless of size or sector. The risk is greater in organizations with:

  • Remote access or VPN with simple credentials
  • Email on own domains (@company.com)
  • Suppliers or subcontractors with access to internal systems
  • OIV obligations or essential services under Law N°21.663

Credentials on the dark web

Employee usernames and passwords circulate on criminal markets after breaches in external services — work platforms, corporate apps or personal services used with the company email.

Undetected access

The attacker enters with valid username and password. There is no exploit or malware. The system sees it as a normal access. The damage can take weeks or months to become apparent.

Regulatory impact

Law N°21.663 requires reporting incidents to ANCI within 3 hours (early warning) and 72 hours (technical report). Not detecting a breach does not exempt from liability — the organization must prove it implemented adequate controls.

How many accounts from your domain are compromised today?

The domain diagnosis analyzes historical and active breaches linked to your organization. No cost, no installation required.

Request free diagnosis
Solution

HEROIC DarkWatch — Real-time breach intelligence

Cynersis implements and manages HEROIC DarkWatch: the platform that continuously monitors the dark web, leak forums and stealer logs to detect compromised corporate credentials linked to your domain.

Continuous domain monitoring

DarkWatch tracks your domain in real time across dark web markets, credential stealer logs and leak forums. Each new detected breach generates an immediate alert.

  • Coverage, Credentials of employees, clients, suppliers and internal systems linked to the domain.
  • Exposed data, Emails, plaintext passwords, hashes, session tokens, IPs and associated personal data.

Detailed breach report

Each incident includes: which account was compromised, in which source it appeared (breach name, date, type), what specific data was exposed and risk level to prioritize the response.

  • Immediate action, The report includes concrete recommendations: force password change, activate MFA or revoke access.
  • History, Retrospective analysis since 2010 to detect old unresolved breaches that still represent active risk. See example →

Law N°21.663 compliance

The National Cybersecurity Agency (ANCI) requires OIVs and essential services to implement access management, incident monitoring and continuity plans. DarkWatch directly supports these requirements.

  • Timely reporting, Early detection enabling compliance with the 3 and 72-hour deadlines for reporting incidents to ANCI.
  • Traceability, Auditable record of each detected breach and action taken to demonstrate diligence during inspections.
Chilean regulatory context

ANCI is already operational. Obligations are enforceable today.

Chile activated its cybersecurity framework in 2025. Organizations that do not act preventively face regulatory, operational and reputational risk.

Cybersecurity Framework Law N°21.663

Creates ANCI and the National CSIRT. Defines 12 categories of essential services and establishes specific obligations for 1,154 qualified OIVs: continuity plan, asset management, monitoring, cybersecurity delegate and incident reporting.

Data Protection Law N°21.719

Requires every organization that processes personal data to implement security measures proportional to the risk. Fines for very serious infractions can reach 4% of annual revenues. Applies to the public and private sectors.

Impact on the supply chain

If your organization sells services to an OIV, article 15 of DS 295 requires reporting detected threats to the client. The OIV's deadlines (3 and 72 hours) are transferred contractually to the supplier. Regulatory exposure is not just for direct OIVs.

Process

From detection to mitigation in three steps

01

Domain diagnosis

Cynersis analyzes your organization's domain and delivers a first report of historical and active breaches: compromised accounts, sources and type of exposed data. No cost, no commitment.

02

Monitoring activation

HEROIC DarkWatch is activated for continuous domain surveillance. Each new detected breach generates an immediate alert with the details of the affected account and the recommended action.

03

Mitigation and follow-up

The Cynersis team accompanies the response: prioritization of critical accounts, forced password resets, MFA implementation and review of active accesses. Local support in English.

Knowing is the first step. The diagnosis takes hours, not weeks.

With just your organization's domain, Cynersis can deliver a preliminary report of detected breaches.

Request domain diagnosis
B2B Decision

Different areas, same urgency

Cybersecurity is today a business decision, not just a technical one. Cynersis delivers clear information for each area involved in the evaluation.

CISO / IT Security

Needs visibility on the real exposure surface of the domain, early warnings and evidence of control to respond to audits and meet ANCI requirements.

CIO / IT Management

Seeks to reduce the risk of incidents from compromised credentials without implementation complexity: a solution that works from day one and delivers visible results quickly.

General Management / Legal

Needs to protect the organization from fines, civil liability and reputational damage resulting from data breaches. Compliance with Laws N°21.663 and N°21.719 is today a corporate risk.

FAQ

Frequently asked questions about cybersecurity and credential protection

They are username and password combinations of your organization's employees that were exposed in data breaches from external services — work platforms, cloud applications, forums or personal services. Cybercriminals collect them, publish them on dark web markets and use them to try to access corporate systems.
The only way to know for certain is through an active scan of the dark web, leak forums and stealer logs linked to your domain. HEROIC DarkWatch performs this analysis continuously and delivers a report with each compromised account, the source of the breach and the type of data exposed. Cynersis offers an initial domain diagnosis at no cost.
Law N°21.663, already in force, creates ANCI and the National CSIRT. Defines 12 categories of essential services and establishes obligations for 1,154 qualified OIVs. If your organization is an OIV, provides services to an OIV, or processes data (Law N°21.719), you have concrete obligations: report incidents within 3 and 72 hours, maintain an operational continuity plan and manage user access. Fines can reach 4% of annual revenues.
An antivirus protects the device; a firewall protects the network perimeter. DarkWatch protects digital identity: it detects when a corporate credential has already been stolen and is circulating outside your network, before it is used to gain entry. The three layers are complementary: most successful breaches occur when an attacker uses legitimate credentials and the antivirus detects nothing unusual.
Activation is immediate once the domain or domains to monitor are defined. The first historical breach report is available within hours. Continuous monitoring operates from day one, with automatic alerts every time a new compromised credential is detected.
Cynersis accompanies the entire process: initial assessment, delivery of the breach report by domain, guidance on prioritizing critical accounts and mitigation recommendations (forced password change, MFA, access review). Support is local and with context of the Chilean regulatory framework.
Yes. Access management and monitoring of compromised credentials are part of the controls required by Framework Law N°21.663 for OIV and essential services. DarkWatch specifically supports the identity and access management requirement and the ability to detect security incidents that must be reported within legal timeframes.
Free diagnosis

Knowing which accounts are compromised is the first step

Share your organization's domain and Cynersis prepares a preliminary breach diagnosis. No installation required, no cost, no commitment.

  • 29 years as a B2B technology integrator · ISO 9001 certified.
  • Official HEROIC DarkWatch partner · Local support in English.
  • Presence in Chile, Peru and Brazil · Local regulatory context.
  • Data used solely to respond to this request.

Your data will be used solely to respond to this commercial request.