# Handle Leaked Data Safely

See what Cyber Threat Intelligence masks on screen, what showing a password does, which leaked data stays visible, and how to handle leaked credentials, exports and dark web results responsibly.

Source: https://docs.deepinfo.com/guide/cti/sensitive-data/

Last updated: 2026-09-26

---
Cyber Threat Intelligence (CTI) shows data found in leaks: your employees' passwords, your customers' logins, payment card data and
posts from dark web sources. This page lists what the platform masks on screen and what it shows as found,
so you can decide what to reveal, export or share.

## Before You Start

This applies to everyone who can open CTI; see [What you can access](/guide/basics/packages-and-roles/).

## Passwords Are Masked

Leaked passwords are masked on screen until you choose to show them:

| Where | How the password appears | How to show it |
|---|---|---|
| [EXPOSED CREDENTIALS](/guide/cti/credential-exposures/) tab, list view | `••••••` in the **PASSWORD** column | Tick **SHOW PASSWORD** |
| Credential drawer, **OVERVIEW** tab | `●●●●●●●●` next to **PASSWORD** | Select the eye icon |
| Quick view and the credential's own page | `••••••` in the **PASSWORD** figure | Use the list view or the drawer |
| Employee's page, **CREDENTIALS** tab | `••••••` in the **PASSWORD** column | Tick **SHOW PASSWORD** |

These screens show no passwords at all:

- the **CREDENTIALS** tab of the employee drawer;
- the **COMPROMISED CLIENTS** list of [Compromised Client Credentials](/guide/cti/compromised-client-credentials/);
- the dashboards and the overview tabs.

**SHOW PASSWORD** is not available in quick view. Switch to list view to use it.

## What Showing a Password Does

Ticking **SHOW PASSWORD**, or selecting the eye icon, shows the password in plain text in your browser.
Anyone who can see your screen can read it. Untick **SHOW PASSWORD** to mask the list again.

Show a password only when you need it, and mask it again as soon as you are done. Before you share your
screen or take a screenshot, check that no password is shown.

## What Stays Visible While Passwords Are Masked

- **Password analysis.** **STRUCTURE** on the **PASSWORD ANALYSIS** tab, and **DOMINANT STRUCTURE** in an
  employee's security profile, show the pattern of character types in a password. **LENGTH**, **CONTAINS**
  and the **YES** / **NO** checks describe it further. Together they reveal the shape of a password without
  its characters. Keep this in mind before you share a screenshot.
- **The Password filter.** On the **EXPOSED CREDENTIALS** tab, **CREDENTIAL** › **Password** filters the list
  by password value, whether or not passwords are shown. Anyone who can use the filters can look for a given
  password in the leaked data.
- **Account details.** Employees' e-mail addresses and details such as department and title, and the
  usernames and e-mail addresses of your customers, are shown as they are.

## Card Data and Dark Web Results

- **Payment cards.** The **COMPROMISED PAYMENTS** list has a **PAN** column for the card number; see
  [Review compromised payment credentials](/guide/cti/compromised-payment-credentials/). Handle everything on
  that page under your organization's rules for card data.
- **Dark web results.** Results of [Dark Web Search](/guide/cti/dark-web-search/) can contain e-mail
  addresses, IP addresses, card numbers, social security numbers and the full text of the source. Handle
  them under the same rules as card data.

## Data Kept in Your Browser

Dark Web Search keeps your search tabs, with their searches and results, in this browser for your user, so
they are still there after a reload. They are not shared with other browsers or computers. On a shared
computer, close the search tabs you no longer need, or clear the browser's site data for the platform when
you finish.

## Exports and Reports

**EXPORT** on the CTI lists and the exports on the **CTI REPORTS** tab of **REPORTS** create files on your
computer. The platform does not describe what each **EXPORT SCOPE** includes, so check an exported file for
passwords and other leaked values before you pass it on. Store exported files securely, share them only with
people who need them, and delete them when you no longer need them.

## Act on Leaked Data Responsibly

- **Use it only to protect the accounts concerned.** For example, have the leaked password changed on every
  service where it was used, and turn on multi-factor authentication where the service offers it. For your
  customers' accounts, follow your own process, such as asking the customer to reset the password.
- **Do not sign in with a leaked credential** to check whether it still works.
- **Do not copy passwords or card numbers** into tickets, e-mail or chat. Refer to a credential by its
  service and account instead, or share the address of its page in the platform.
- **Follow your organization's policies** for personal data and incident response.
- **Record what you did** by changing the credential's state; see
  [Change the state of exposed credentials](/guide/cti/change-credential-state/).

## Good to Know

- **Screenshots.** Take screenshots of CTI screens with passwords masked, and check the password analysis
  fields and e-mail addresses before you share them.

## Do This With the API

The search responses include the `password` field of each employee and client credential, and the card
number fields (`pan`, `pan_masked`, `pan_last_four`) of each payment record. Protect the responses, and any
files or logs your scripts write, as you would the platform's screens:

- [Compromised Employee Credential Search](/reference/cti/compromised-employee-credential-search/)
- [Compromised Client Credential Search](/reference/cti/compromised-client-credential-search/)
- [Compromised Payment Credential Search](/reference/cti/compromised-payment-credential-search/)
