The practical reasons

Why Do Hackers Use Tor?

For the same core reason anyone uses it — to separate an identity from an activity — applied to a specific, less benign set of activities.

Hackers use Tor primarily to hide their real IP address and location while conducting attacks, communicating with buyers of stolen data, coordinating on forums, and accessing dark web marketplaces without exposing their identity. It's one tool among several in a typical attacker's operational security toolkit, not a complete anonymity solution on its own — many hackers who rely on it exclusively still get caught through other mistakes.

Tor's anonymity properties are genuinely neutral — they don't distinguish between a journalist protecting a source and an attacker covering their tracks.

That neutrality is exactly why hackers rely on it as one tool among several, for some very specific practical reasons.

A hooded figure's location scattered across several relay points on a map
Primary useHiding IP address and location during operations
Secondary useAccessing criminal forums and marketplaces
Common failure pointCombining Tor with other careless operational habits

TL;DR

Quick answer

Hackers use Tor primarily to hide their IP address and location during attacks and to communicate with buyers or collaborators without exposing their identity. It's one part of a broader operational security toolkit — most hackers who are eventually caught are unmasked through unrelated mistakes, not a failure of Tor itself.

Last reviewed2026-07-25
Reading time6 min
DifficultyBeginner
EvidenceModerate
Main drawIP address and location concealment
Also used bySecurity researchers investigating the same hackers
Reliability aloneNot sufficient — often combined with other opsec measures
Common mistakeReusing usernames or habits across anonymous and real identities
Legal status of the tool itselfLegal; illegal only in how it's applied

The setup

The same protection, applied to a less benign purpose

Tor's core function — separating identity from activity — is exactly as useful to an attacker as it is to a journalist. For a hacker, that typically means routing command-and-control traffic, communications with buyers or collaborators, and access to marketplaces and forums through Tor so investigators can't easily trace those connections back to a real IP address.

It's rarely the only precaution a sophisticated attacker takes. Security researchers and law enforcement have repeatedly found that hackers relying on Tor alone, without broader operational discipline, still get caught — usually through unrelated mistakes like reused usernames, sloppy communication habits, or outdated software.

The main reasons, specifically

  • Hiding a real IP address and physical location during active operations.
  • Communicating with buyers, collaborators, or forums without exposing identity.
  • Accessing dark web marketplaces to sell stolen data or purchase tools.

The people investigating hackers often use the exact same tool

This means, on any given day, some fraction of Tor's traffic connecting to a criminal forum may actually be researchers rather than criminals.

Cybersecurity researchers and law enforcement investigators frequently use Tor themselves — to browse suspect forums or command-and-control infrastructure without revealing an identifiable government or corporate IP address that could tip off the very target they're studying.

It's a clean illustration of Tor's genuine neutrality — the same protection serves both sides of a cat-and-mouse investigation simultaneously.

What people get wrong

Myth

Using Tor makes a hacker completely untraceable.

Reality

Tor protects routing, not behavior — sloppy habits like reused usernames or outdated software have led to most documented unmaskings of hackers who relied on it.

Myth

Only criminals have a reason to use Tor for their work.

Reality

Security researchers, penetration testers, and law enforcement investigators use it too, often for the exact same core reason: hiding their identity from whoever they're interacting with.

Myth

Tor is specifically built for hacking.

Reality

It's general-purpose anonymity software; hackers are one category of users among journalists, activists, and ordinary privacy-conscious people.

If Tor hides IP addresses so effectively, why do sophisticated hackers still get caught?

Given Tor's strong track record against direct network attacks, why doesn't it reliably protect hackers who rely on it?

Because Tor only protects one specific layer — network routing. It does nothing to prevent a hacker from reusing a distinctive username across an anonymous forum and an old, identifiable account, writing in a recognizable style, making a careless purchase with traceable payment details, or simply bragging to the wrong person. Investigators have repeatedly built successful cases by working around Tor entirely, focusing on exactly these kinds of behavioral and operational mistakes instead.

Some ransomware groups run their own onion sites as part of the extortion process

Several ransomware operations maintain dedicated onion sites specifically to publish stolen data from victims who refuse to pay, using Tor's hosting anonymity to keep those extortion sites running despite active law enforcement attention.

It shows Tor being used not just to hide an individual attacker's identity, but as core infrastructure for an entire criminal business model.

The tool built to protect the vulnerable gets used to protect the people threatening them

Tor's original design goal was protecting people at risk from powerful adversaries — governments, surveillance states. Hackers extorting individuals and companies represent almost the inverse relationship, using that same protection to threaten people with comparatively less power to fight back.

Ransomware leak sites surviving repeated takedown attempts

Several major ransomware groups' onion-hosted leak sites have gone offline and reappeared multiple times after law enforcement disruption attempts, illustrating the resilience Tor hosting provides even under sustained pressure.

It's a concrete demonstration of Tor's hosting anonymity being actively exploited as durable criminal infrastructure, not just a one-time hiding tactic.

confirmed

So, why do they use it?

Primarily to hide their IP address and location during attacks and communications — one part of a broader operational security toolkit, not a complete solution on its own.

The same reason anyone uses Tor: to separate identity from activity — just applied to activity that's often illegal.

Neutral tools always end up serving both sides of a conflict

This is a pattern that shows up with encryption, VPNs, and plenty of other privacy technology: whatever protection it offers gets used by defenders and attackers alike. Understanding why hackers use Tor is less about Tor being uniquely dangerous and more about anonymity itself being genuinely useful to anyone trying to avoid detection, for whatever reason.

The short version

  • Hackers primarily use Tor to hide their IP address and location during attacks and communications.
  • It's also used to access dark web marketplaces and criminal forums without exposing identity.
  • Security researchers and law enforcement use the same tool for their own investigative purposes.
  • Tor alone doesn't guarantee anonymity — most unmasked hackers were caught through unrelated behavioral mistakes.

Questions people ask

Where to go next

Can the dark web be hacked?

The flip side of this question — how hackers themselves become targets.

Is Tor safe from police?

Why Tor alone hasn't been enough to protect hackers who rely on it.

Who stopped WannaCry?

A related look at how a major cyberattack actually got resolved.

Why is Tor Browser good or safe?

The same protections discussed here, from the perspective of legitimate users.

What happens to seized dark web cryptocurrency?

What often follows once a hacker's operations are eventually traced.

The same shield, pointed the other way

Hackers use Tor for exactly the reason anyone does — it just happens to be pointed at something worth catching, rather than something worth protecting.

You now know

  • Hackers primarily use Tor to hide their IP address and location during attacks and communications.
  • It's also used to access dark web marketplaces and criminal forums without exposing identity.
  • Tor alone doesn't guarantee anonymity — most unmasked hackers were caught through unrelated behavioral mistakes.

Safety note

Educational, not operational

This guide is educational. It does not provide instructions for illegal activity, evading law enforcement, buying prohibited goods, or attacking systems. Laws and risks vary by country, so stay within your local rules and avoid interacting with unknown services.

Common myth

Myth vs reality

Myth

Using Tor makes a hacker completely untraceable.

Reality

Tor protects routing, not behavior — sloppy habits like reused usernames or outdated software have led to most documented unmaskings of hackers who relied on it.

FAQs

Questions people ask

Sources

Further reading

  • Cybersecurity research on ransomware leak site infrastructure and attacker operational securityVarious security research sources

Continue learning

Next useful step

Keep going

The next door is usually the interesting one

The answer you came for touches a few neighboring questions. These are the ones most likely to make the picture click.

What you should remember

The same shield, pointed the other way

  • Hackers use Tor for exactly the reason anyone does — it just happens to be pointed at something worth catching, rather than something worth protecting.
  • Hackers primarily use Tor to hide their IP address and location during attacks and communications.
  • It's also used to access dark web marketplaces and criminal forums without exposing identity.
  • Tor alone doesn't guarantee anonymity — most unmasked hackers were caught through unrelated behavioral mistakes.

A few useful next steps

Where this question wanders next

The dark web is less a single tunnel than a set of side passages. These are the useful ones from here.

If this made you wonder

tor collection

Follow the causes

1

What Are Onion Sites Used For?

A wider range of purposes than the stereotype suggests — some mundane, some genuinely important, some exactly what you'd expect.

2

What Are the Uses of Hidden Services on the Tor Network?

The New York Times runs one. So does a whistleblower drop box used by dozens of newsrooms. And, yes, so do some marketplaces you've heard of. Here's the full range.

3

What Do Hackers Hate the Most?

Most cyberattacks aren't a battle of wits against a determined genius — they're a cost-benefit calculation, and a handful of unglamorous defenses tip that math dramatically.

4

What Is Tor Browser Used For?

Ask people what Tor Browser is for, and most will guess the dark web. Ask the Tor Project's own usage data, and you get a considerably longer, more ordinary list.

5

Best Dark Web Search Engines 2026

There's no dark web Google. What exists instead is a small set of tools that trade off coverage against safety in very different ways.

Questions people ask first

Choose by the time in your pocket