# Review Compromised Client Credentials

See your customers' credentials for your services that were found in leaked data, with the login address, the state of each credential and an exposure timeline, and export them.

Source: https://docs.deepinfo.com/guide/cti/compromised-client-credentials/

Last updated: 2026-09-26

---
Compromised Client Credentials lists the credentials of your customers for your own services that were found
in leaked data. Use it to see which customer accounts are exposed and on which login pages.

## Before You Start

- **Package:** Cyber Threat Intelligence (CTI).
- **Role:** Admin or Member.

## Where to Find It

**Sidebar:** **CYBER THREAT INTELLIGENCE** › **COMPROMISED CLIENT CREDENTIALS** · **Tab:** **COMPROMISED CLIENTS** · https://platform.deepinfo.com/app/cti/compromised-client-credentials/list

The page title is **Compromised Client Credentials**, with two tabs: **OVERVIEW**
(https://platform.deepinfo.com/app/cti/compromised-client-credentials) and **COMPROMISED CLIENTS**. The
sidebar item opens **COMPROMISED CLIENTS**. The **GO TO COMPROMISED CLIENT CREDENTIALS PAGE** button on the
[CTI dashboard](/guide/cti/dashboard/) opens the page too.

## Read the OVERVIEW Tab

The breadcrumb reads **CTI / COMPROMISED CLIENT CREDENTIALS / OVERVIEW**.

- **COMPROMISED CLIENTS**: the number of compromised client credentials, with a change indicator marked
  **BY YEAR**.
- **CREDENTIAL EXPOSURE TIMELINE**: exposed client credentials per period.
- **RECENTLY EXPOSED CLIENTS**: the latest client credentials, each with the client's e-mail address and the
  date it was found.

![The OVERVIEW tab of Compromised Client Credentials with the count card, the exposure timeline and the recently exposed clients, with e-mail addresses blurred.](/img/guide/cti/compromised-client-credentials-01.png)

## Read the COMPROMISED CLIENTS Tab

The breadcrumb reads **CTI / COMPROMISED CLIENT CREDENTIALS / COMPROMISED CLIENTS**. From top to bottom:

1. **Filter row:** the **SEARCH** box and the filter chips **CREDENTIAL**, **ACCOUNT TYPE**, **PASSWORD**,
   **STATUS** and **TARGET**.
2. **Result line:** **\<n\> COMPROMISED CLIENTS FOUND**, **SHOW INACTIVES**, **EXPORT** and **VIEW SETTINGS**.
3. **Tab:** **ALL CLIENTS**, with the count.
4. **The list:**

| Column | What it shows |
|---|---|
| **USERNAME** | The customer's username or e-mail address |
| **TARGET** | The login address the credential belongs to, with its platform and domain |
| **STATE** | The credential's state, for example **ACTIVE · NEWLY DETECTED** or **ACTIVE · UNRESOLVED** |
| **ADDED DATE** | When the credential was added |

The list shows no passwords. Tick **SHOW INACTIVES** to include credentials in an inactive state; the states
are explained in [Change the state of exposed credentials](/guide/cti/change-credential-state/).

The filter chips work like the other CTI lists; see
[Search, filter and export lists](/guide/basics/lists-filters-and-exports/).

![The COMPROMISED CLIENTS tab with the filter chips and the list, with usernames and targets blurred.](/img/guide/cti/compromised-client-credentials-02.png)

## Export the List

1. Filter the list if you want only part of it.
2. Select **EXPORT**. The **DOWNLOAD** window opens.
3. Choose **RECORDS** (**ALL** or **FILTERED**), **FILE FORMAT** (**CSV** or **JSON**) and **EXPORT SCOPE**
   (**DEFAULT**, **BASIC** or **EXTENDED**).
4. Select **EXPORT**.

## Good to Know

- **Full export.** The **CTI REPORTS** tab of **REPORTS** has **All Compromised Client Credentials Report**,
  a CSV or JSON file of every client credential. See
  [Export all data as CSV or JSON](/guide/reports/export-data/).
- **Alerts.** A notification rule on **New Client Credential Detected** tells you when a new client
  credential is found. It can be filtered by **Username Type** (**Email** or **Username**). See
  [Create a notification rule](/guide/notifications/create-a-rule/).
- **Handle with care.** Client credentials belong to your customers; see
  [Handle leaked data safely](/guide/cti/sensitive-data/).

## Do This With the API

- [Compromised Client Credential Search](/reference/cti/compromised-client-credential-search/)
- [Compromised Client Credential Export](/reference/cti/compromised-client-credential-export/)
- [Compromised Client Credential Stats](/reference/cti/compromised-client-credential-stats/)
- State changes: [Compromised Client Credential Ignore](/reference/cti/compromised-client-credential-ignore/)
  and the related actions listed in
  [Change the state of exposed credentials](/guide/cti/change-credential-state/).

The API responses include the `password` field of each client credential. Handle them as described in
[Handle leaked data safely](/guide/cti/sensitive-data/).
