# Investigate Compromised Employees

Find the employees whose accounts appear in leaked credential data, see their risk level and password habits, review their exposed credentials, correct their details and export the list.

Source: https://docs.deepinfo.com/guide/cti/compromised-employees/

Last updated: 2026-09-26

---
The **COMPROMISED EMPLOYEES** tab lists every employee account of your organization that was found in leaked
credential data. Use it to find the riskiest accounts, see how their passwords were built and reused, and
open each employee's credentials.

## Before You Start

- **Package:** Cyber Threat Intelligence (CTI).
- **Role:** Admin or Member.

## Where to Find It

**Sidebar:** **CYBER THREAT INTELLIGENCE** › **COMPROMISED EMPLOYEE DATA** · **Tab:** **COMPROMISED EMPLOYEES** · https://platform.deepinfo.com/app/cti/compromised-employee-data/list

The sidebar item opens this tab. The breadcrumb reads
**CTI / COMPROMISED EMPLOYEE DATA / COMPROMISED EMPLOYEES**.

## Read the List

From top to bottom:

1. **Filter row:** the **SEARCH** box; the filter chips **IDENTITY**, **EXPOSURE**, **PASSWORD BEHAVIOR**,
   **REUSE ANALYSIS**, **COMPOSITION**, **TEMPORAL**, **RISK** and **STATE**, some of which appear only after
   you select **SHOW ALL FILTERS ›**; and, on the right, the icons that switch between quick view and list
   view.
2. **Result line:** **\<n\> COMPROMISED EMPLOYEES FOUND**, **EXPORT** and **VIEW SETTINGS**.
3. **Domain tabs:** **ALL EMPLOYEES**, then one tab per domain of your organization, each with its count.
   Select a tab to list only that domain's employees.
4. **The list,** 25 rows per page by default:

| Column | What it shows |
|---|---|
| **EMPLOYEE** | The risk level (a bar and **CRITICAL**, **HIGH**, **MEDIUM** or **LOW**), the e-mail address and the domain |
| **DEPARTMENT** | The employee's department, when known |
| **PASSWORDS** | The number of unique leaked passwords, with a red **WEAK PASSWORD: \<n\>** chip |
| **REUSE** | The share of reused passwords, in % |
| **LAST EXPOSURE** | The date of the latest exposure, with the time since then |

The list is sorted by **LAST EXPOSURE**, newest first. To sort by another column, select the sort icon in
its header. **VIEW SETTINGS** opens **View Options**: **Sort By**, **Result Per Page** (25, 50, 75 or 100),
**Reset to Default View**, and the **SHOWN** list of columns.

![The COMPROMISED EMPLOYEES tab with the filter row, the domain tabs and the employee list, with e-mail addresses and domains blurred.](/img/guide/cti/compromised-employees-01.png)

## Filter the List

Select a filter chip to add a condition on one of its fields: choose the field, the rule (**Must**,
**Must Not** or **Should**), the operator and the value, then select **APPLY**. **Add New** adds another
condition and **Clear All** removes them. The general filter controls are described in
[Search, filter and export lists](/guide/basics/lists-filters-and-exports/).

| Chip | Fields |
|---|---|
| **IDENTITY** | Email, Domain, Is Executive, First Name, Last Name, Title, LinkedIn URL, Department |
| **EXPOSURE** | First Exposure Date, Last Exposure Date, Exposure Span Days |
| **PASSWORD BEHAVIOR** | Unique Password Count, Avg Password Length, Avg Strength Score, Min Strength Score, Max Strength Score, Very Weak Password Count, Weak Password Count, Medium Password Count, Strong Password Count, Very Strong Password Count, Weak Password Percentage |
| **REUSE ANALYSIS** | Password Reuse Count, Password Reuse Percentage |
| **COMPOSITION** | Common Password Count, Dictionary Word Count, Keyboard Pattern Count, Date Pattern Count, Avg Character Classes, All Four Classes Percentage, Dominant Structure, Structure Variety Count |
| **TEMPORAL** | Days Since Last Exposure, Exposure Accelerating, Exposure Velocity |
| **RISK** | Risk Score, Risk Level |
| **STATE** | State, Total Credentials, Active Credential Count, Inactive Credential Count, Unresolved Credential Count, Resolved Credential Count, Risk Accepted Credential Count, Ignored Credential Count, False Positive Credential Count |

The **STATE** chip is useful for follow-up: for example, **Active Credential Count** finds the employees who
still have active credentials.

## Open an Employee

Select a row. A drawer opens on the right:

- At the top: **OPEN IN NEW TAB**, which opens the employee's own page; the risk level, e-mail address and
  domain; and a **⋮** menu with **EDIT DETAILS**.
- On the left, three icon tabs. Hover over an icon to see its name.

| Tab | What it shows |
|---|---|
| **OVERVIEW** | **DEPARTMENT**, **TITLE**, **FIRST EXPOSURE DATE** and **LAST EXPOSURE DATE**, then **INSIGHTS**: **PASSWORDS** with a breakdown into **VERY WEAK**, **WEAK**, **MEDIUM**, **STRONG** and **VERY STRONG**; **AVG STRENGTH SCORE** (out of 10); **REUSE RATE** (%); **VELOCITY** (credentials per month) |
| **SECURITY PROFILE** | The four blocks described under [Security profile](#security-profile) |
| **CREDENTIALS** | The employee's leaked credentials: **CREDENTIAL** (service, platform and host) and **STATE**. Tick **SHOW INACTIVES** to include inactive ones. This tab shows no passwords |

![The employee drawer on the OVERVIEW tab, with the e-mail address and the domain blurred.](/img/guide/cti/compromised-employees-02.png)

## Open the Employee's Page

Select **OPEN IN NEW TAB** in the drawer, or a row of **RECENTLY EXPOSED EMPLOYEES** on the
[CTI dashboard](/guide/cti/dashboard/) or the [overview](/guide/cti/compromised-employee-data/). The
breadcrumb reads **CTI / COMPROMISED EMPLOYEE DATA / EMPLOYEES / \<e-mail address\>**.

The header shows the e-mail address, the domain, a **⋮** menu with **EDIT DETAILS**, and four figures:

| Figure | The platform's description |
|---|---|
| **RISK LEVEL** | "Composite priority based on credential, role, and recency." |
| **CREDENTIAL LEAK** | "Count of credentials exposed in historical data leaks." |
| **UNIQUE PASSWORDS** | "Total number of non-duplicate passwords in use." |
| **AVG STRENGTH SCORE** | "Mean security score of the current password set." |

Below are two tabs:

- **SECURITY PROFILE** (open first): the four blocks described below.
- **CREDENTIALS**, with the number of credentials: a **SEARCH** box, **SHOW INACTIVES**, **SHOW PASSWORD**,
  and a checkbox in the header to select rows. The columns are **CREDENTIAL**, **STATE**, **PASSWORD**
  (masked), **STRENGTH** and **ADDED DATE**. Select a row to open the credential.

To show the passwords, see [Handle leaked data safely](/guide/cti/sensitive-data/).

![An employee's page with the header figures and the SECURITY PROFILE tab; the e-mail address and DOMINANT STRUCTURE are blurred.](/img/guide/cti/compromised-employees-03.png)

## Security Profile

The drawer and the employee's page show the same four blocks. On the employee's page, each block carries
the platform's description of it.

| Block | Description | Figures |
|---|---|---|
| **EXPOSURE TIMELINE** | "When this account was first detected, how long the exposure has run and whether the rate is rising." | **FIRST SEEN**, **LAST SEEN**, **EXPOSURE SPAN**, **DAYS SINCE LAST**, **VELOCITY**, **TREND** (for example **STABLE**) |
| **PASSWORD BEHAVIOR** | "Comprehensive analysis of user password habits and security compliance." | **UNIQUE PASSWORDS**, **AVG STRENGTH SCORE**, **WEAK PASSWORDS**, **AVG LENGTH**, **MIN / MAX SCORE** |
| **REUSE & PATTERNS** | "Analysis of identical passwords used across multiple platforms and common character sequences." | **REUSE RATE**, **REUSED PASSWORDS** |
| **COMPOSITIONS** | "Distribution of password elements such as uppercase letters, numbers, and special characters." | **COMMON PASSWORDS**, **DICTIONARY WORDS**, **DOMINANT STRUCTURE**, **AVG CHAR CLASSES**, **ALL CHAR CLASSES**, **STRUCTURE VARIETY**, **KEYBOARD PATTERNS**, **DATE PATTERNS** |

**DOMINANT STRUCTURE** shows the pattern of character types in the employee's passwords. It stays visible
while passwords are masked; see [Handle leaked data safely](/guide/cti/sensitive-data/).

## Edit an Employee's Details

You can add or correct the details the platform holds for an employee, such as the name, title, department
and whether the person is an executive. The **IDENTITY** filters use these details.

1. Open the employee's drawer or page.
2. Open the **⋮** menu and select **EDIT DETAILS**.
3. The **Edit Information** drawer opens: "You can edit the information for this employee account." Change
   any of **FIRST NAME**, **LAST NAME**, **CURRENT TITLE**, **DEPARTMENT**, **LINKEDIN URL** and
   **EXECUTIVE**. **EMAIL ADDRESS** cannot be changed.
4. Select **UPDATE**. The button becomes active once you change a field.

To leave without saving, select **CANCEL**.

![The Edit Information drawer of an employee with CANCEL and UPDATE at the bottom; the e-mail address is blurred.](/img/guide/cti/compromised-employees-04.png)

## Export the List

1. Filter the list if you want only part of it.
2. Select **EXPORT**. The **DOWNLOAD** window opens: "Choose the records, format, and level of detail for
   your export."
3. Choose:
   - **RECORDS**: **ALL**, or **FILTERED** for the records that match your filters;
   - **FILE FORMAT**: **CSV** or **JSON**;
   - **EXPORT SCOPE**: **DEFAULT**, **BASIC** or **EXTENDED**.
4. Select **EXPORT**. **CANCEL** closes the window without a download.

The file name starts with `COMPROMISED-EMPLOYEE-ACCOUNTS`, followed by the date and time.

## Good to Know

- **Password counts.** **PASSWORDS** and **UNIQUE PASSWORDS** count unique passwords, and
  **CREDENTIAL LEAK** counts credentials. The strength breakdown under **INSIGHTS** and the red
  **WEAK PASSWORD** chip can count credentials too, so they can show more than **PASSWORDS**.
- **States are set per credential.** To close an employee's credentials, see
  [Change the state of exposed credentials](/guide/cti/change-credential-state/).
- **Passwords are elsewhere.** The drawer's **CREDENTIALS** tab has no passwords. Use the employee's page or
  the [EXPOSED CREDENTIALS](/guide/cti/credential-exposures/) tab.

## Do This With the API

- [Compromised Employee Account Search](/reference/cti/compromised-employee-account-search/)
- [Compromised Employee Account Detail](/reference/cti/compromised-employee-account-detail/)
- [Compromised Employee Account Update](/reference/cti/compromised-employee-account-update/)
- [Compromised Employee Account Export](/reference/cti/compromised-employee-account-export/)
- [Search & filters](/getting-started/search-and-filters/): the **MUST**, **MUST NOT** and **SHOULD** model
  the filter chips use.
