# Review Compromised Payment Credentials

See the payment card data related to your organization that was found in leaked data, with where it came from, how often it was seen and its state, and export it.

Source: https://docs.deepinfo.com/guide/cti/compromised-payment-credentials/

Last updated: 2026-09-26

---
Compromised Payment Credentials lists payment card data related to your organization that was found in
leaked data. Use it to see which cards are exposed, where the records come from and how often each card
was seen.

## Before You Start

- **Package:** Cyber Threat Intelligence (CTI).
- **Role:** Admin or Member.
- **Data:** the page stays empty until payment card data is found for your organization. Until then, the
  **COMPROMISED PAYMENTS** count shows **-** and the lists show **No Result Found.**

## Where to Find It

**Sidebar:** **CYBER THREAT INTELLIGENCE** › **COMPROMISED PAYMENT CREDENTIALS** · **Tab:** **COMPROMISED PAYMENTS** · https://platform.deepinfo.com/app/cti/compromised-payment-credentials/list

The page has two tabs: **OVERVIEW**
(https://platform.deepinfo.com/app/cti/compromised-payment-credentials) and **COMPROMISED PAYMENTS**. The
sidebar item opens **COMPROMISED PAYMENTS**. The **GO TO COMPROMISED PAYMENT CREDENTIALS PAGE** button on the
[CTI dashboard](/guide/cti/dashboard/) opens the page too.

## Read the OVERVIEW Tab

- **COMPROMISED PAYMENTS**: the number of compromised payment records, with a change indicator marked
  **BY YEAR**.
- **CREDENTIAL EXPOSURE TIMELINE**: exposed payment records per period.
- **RECENTLY EXPOSED PAYMENTS**: the latest payment records.

## Read the COMPROMISED PAYMENTS Tab

The breadcrumb reads **CTI / COMPROMISED PAYMENT CREDENTIALS / COMPROMISED PAYMENTS**. From top to bottom:

1. **Filter row:** the **SEARCH** box and the filter chips **CARD**, **ISSUER**, **VALIDATION** and
   **EXPOSURE**.
2. **Result line:** the number of records found, **EXPORT** and **VIEW SETTINGS**.
3. **Tab:** **ALL CARDS**, with the count.
4. **The list:**

| Column | What it shows |
|---|---|
| **PAN** | The card number (primary account number) |
| **CONFIDENCE** | The platform's confidence level for the record |
| **SOURCE** | The source the record comes from |
| **HACKISHNESS** | A hackishness score, as on [dark web search](/guide/cti/dark-web-search/) results |
| **TIMES SEEN** | How many times the card was seen |
| **STATE** | The record's state; see [Change the state of exposed credentials](/guide/cti/change-credential-state/) |
| **LAST SEEN** | When the card was last seen |

The filter chips work like the other CTI lists; see
[Search, filter and export lists](/guide/basics/lists-filters-and-exports/).

![The COMPROMISED PAYMENTS tab with its filter chips and columns, showing No Result Found.](/img/guide/cti/compromised-payment-credentials-01.png)

## Export the List

1. Filter the list if you want only part of it.
2. Select **EXPORT**. The **DOWNLOAD** window opens.
3. Choose **RECORDS** (**ALL** or **FILTERED**), **FILE FORMAT** (**CSV** or **JSON**) and **EXPORT SCOPE**
   (**DEFAULT**, **BASIC** or **EXTENDED**).
4. Select **EXPORT**.

## Good to Know

- **Full export.** The **CTI REPORTS** tab of **REPORTS** has **All Compromised Payment Credentials Report**,
  described as including the card brand, BIN and current status. See
  [Export all data as CSV or JSON](/guide/reports/export-data/).
- **Alerts.** A notification rule on **New Payment Credential Detected** tells you when new card data is
  found. It can be filtered by **Card Brand** (**Visa**, **Mastercard**, **Amex**, **Discover**,
  **UnionPay**) and **BIN**. See [Create a notification rule](/guide/notifications/create-a-rule/).
- **Handle with care.** Card data is sensitive; see [Handle leaked data safely](/guide/cti/sensitive-data/).

## Do This With the API

- [Compromised Payment Credential Search](/reference/cti/compromised-payment-credential-search/)
- [Compromised Payment Credential Detail](/reference/cti/compromised-payment-credential-detail/)
- [Compromised Payment Credential Export](/reference/cti/compromised-payment-credential-export/)
- [Compromised Payment Credential Stats](/reference/cti/compromised-payment-credential-stats/)
- State changes: [Compromised Payment Credential Ignore](/reference/cti/compromised-payment-credential-ignore/)
  and the related actions listed in
  [Change the state of exposed credentials](/guide/cti/change-credential-state/).
