# Compromised Employee Account Detail

GET /cti/compromised-employee-accounts/{account_id}: Returns one compromised employee account.

Source: https://docs.deepinfo.com/reference/cti/compromised-employee-account-detail/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/compromised-employee-accounts/{account_id}`

Returns one compromised employee account.

## Authentication

Send your API key in the `apikey` request header.

## Path Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `account_id` | Required |  | `000000000000000ec9430001` |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `id` | string |  |
| `email` | string |  |
| `domain` | string |  |
| `is_executive` | boolean |  |
| `first_name` | string |  |
| `last_name` | string |  |
| `title` | string |  |
| `linkedin_url` | string |  |
| `department` | string |  |
| `security_profile` | object |  |
| `computed_state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `state_stats` | object |  |
| `risk_score` | integer |  |
| `risk_level` | string | One of `low`, `medium`, `high`, `critical` |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `id` | string |
| `email` | string |
| `domain` | string |
| `is_executive` | boolean |
| `first_name` | null |
| `last_name` | null |
| `title` | null |
| `linkedin_url` | null |
| `department` | null |
| `security_profile` | object |
| `security_profile.exposure` | object |
| `security_profile.exposure.first_exposure_date` | string |
| `security_profile.exposure.last_exposure_date` | string |
| `security_profile.exposure.exposure_span_days` | number |
| `security_profile.password_behavior` | object |
| `security_profile.password_behavior.unique_password_count` | number |
| `security_profile.password_behavior.avg_password_length` | number |
| `security_profile.password_behavior.avg_strength_score` | number |
| `security_profile.password_behavior.min_strength_score` | number |
| `security_profile.password_behavior.max_strength_score` | number |
| `security_profile.password_behavior.strength_distribution` | object |
| `security_profile.password_behavior.strength_distribution.very_weak` | number |
| `security_profile.password_behavior.strength_distribution.weak` | number |
| `security_profile.password_behavior.strength_distribution.medium` | number |
| `security_profile.password_behavior.strength_distribution.strong` | number |
| `security_profile.password_behavior.strength_distribution.very_strong` | number |
| `security_profile.password_behavior.weak_password_percentage` | number |
| `security_profile.reuse_analysis` | object |
| `security_profile.reuse_analysis.password_reuse_count` | number |
| `security_profile.reuse_analysis.password_reuse_percentage` | number |
| `security_profile.composition` | object |
| `security_profile.composition.common_password_count` | number |
| `security_profile.composition.dictionary_word_count` | number |
| `security_profile.composition.keyboard_pattern_count` | number |
| `security_profile.composition.date_pattern_count` | number |
| `security_profile.composition.avg_character_classes` | number |
| `security_profile.composition.all_four_classes_percentage` | number |
| `security_profile.composition.dominant_structure` | string |
| `security_profile.composition.structure_variety_count` | number |
| `security_profile.temporal` | object |
| `security_profile.temporal.credential_timeline` | array<object> |
| `security_profile.temporal.credential_timeline[].year` | number |
| `security_profile.temporal.credential_timeline[].month` | number |
| `security_profile.temporal.credential_timeline[].count` | number |
| `security_profile.temporal.exposure_velocity` | number |
| `security_profile.temporal.exposure_accelerating` | boolean |
| `security_profile.temporal.days_since_last_exposure` | number |
| `computed_state` | string |
| `state_stats` | object |
| `state_stats.total` | number |
| `state_stats.active_count` | number |
| `state_stats.inactive_count` | number |
| `state_stats.unresolved_count` | number |
| `state_stats.resolved_count` | number |
| `state_stats.risk_accepted_count` | number |
| `state_stats.ignored_count` | number |
| `state_stats.false_positive_count` | number |
| `risk_score` | number |
| `risk_level` | string |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/cti/compromised-employee-accounts/000000000000000ec9430001' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "id": "000000000000000ec9430001",
  "email": "user@acme.example",
  "domain": "acme.example",
  "is_executive": false,
  "first_name": null,
  "last_name": null,
  "title": null,
  "linkedin_url": null,
  "department": null,
  "security_profile": {
    "exposure": {
      "first_exposure_date": "2025-06-01T08:00:00Z",
      "last_exposure_date": "2025-07-31T08:00:00Z",
      "exposure_span_days": 60
    },
    "password_behavior": {
      "unique_password_count": 3,
      "avg_password_length": 9,
      "avg_strength_score": 44,
      "min_strength_score": 25,
      "max_strength_score": 62,
      "strength_distribution": {
        "very_weak": 1,
        "weak": 1,
        "medium": 1,
        "strong": 0,
        "very_strong": 0
      },
      "weak_password_percentage": 67
    },
    "reuse_analysis": {
      "password_reuse_count": 1,
      "password_reuse_percentage": 33
    },
    "composition": {
      "common_password_count": 0,
      "dictionary_word_count": 0,
      "keyboard_pattern_count": 0,
      "date_pattern_count": 0,
      "avg_character_classes": 3,
      "all_four_classes_percentage": 50,
      "dominant_structure": "********",
      "structure_variety_count": 1
    },
    "temporal": {
      "credential_timeline": [
        {
          "year": 2025,
          "month": 6,
          "count": 34
        },
        {
          "year": 2025,
          "month": 7,
          "count": 35
        }
      ],
      "exposure_velocity": 0.5,
      "exposure_accelerating": false,
      "days_since_last_exposure": 30
    }
  },
  "computed_state": "unresolved",
  "state_stats": {
    "total": 38,
    "active_count": 2,
    "inactive_count": 20,
    "unresolved_count": 33,
    "resolved_count": 13,
    "risk_accepted_count": 21,
    "ignored_count": 30,
    "false_positive_count": 38
  },
  "risk_score": 20,
  "risk_level": "low"
}
```

### 404 · Not Found (nonexistent account_id)

```bash
curl 'https://api.deepinfo.com/v1/cti/compromised-employee-accounts/ffffffffffffffffffffffff' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 30003,
  "details": [
    "Compromised Employee Account with id=ffffffffffffffffffffffff does not exist."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
