# Compromised Employee Account Search

POST /cti/compromised-employee-accounts/search: Searches employee accounts found in leaked credentials.

Source: https://docs.deepinfo.com/reference/cti/compromised-employee-account-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-employee-accounts/search`

Searches employee accounts found in leaked credentials.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `security_profile.exposure.first_exposure_date` | When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time). |
| `security_profile.exposure.last_exposure_date` | When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first. |
| `security_profile.exposure.exposure_span_days` | The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day. |
| `security_profile.password_behavior.unique_password_count` | The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column. |
| `security_profile.password_behavior.avg_password_length` | The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH). |
| `security_profile.password_behavior.avg_strength_score` | The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10. |
| `security_profile.password_behavior.min_strength_score` | The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE). |
| `security_profile.password_behavior.max_strength_score` | The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE). |
| `security_profile.password_behavior.strength_distribution.very_weak` | The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.weak` | The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.medium` | The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.strong` | The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.very_strong` | The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.weak_password_percentage` | The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS). |
| `security_profile.reuse_analysis.password_reuse_count` | The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS). |
| `security_profile.reuse_analysis.password_reuse_percentage` | The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column). |
| `security_profile.composition.common_password_count` | The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS. |
| `security_profile.composition.dictionary_word_count` | The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS. |
| `security_profile.composition.keyboard_pattern_count` | The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS. |
| `security_profile.composition.date_pattern_count` | The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS. |
| `security_profile.composition.avg_character_classes` | The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES). |
| `security_profile.composition.all_four_classes_percentage` | The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES). |
| `security_profile.composition.structure_variety_count` | The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY). |
| `security_profile.temporal.days_since_last_exposure` | The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST. |
| `security_profile.temporal.exposure_velocity` | How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo). |
| `state_stats.total` | The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group). |
| `state_stats.active_count` | The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count). |
| `state_stats.inactive_count` | The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count). |
| `state_stats.unresolved_count` | The number of the employee's credentials that are unresolved (Unresolved Credential Count). |
| `state_stats.resolved_count` | The number of the employee's credentials that are resolved (Resolved Credential Count). |
| `state_stats.risk_accepted_count` | The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count). |
| `state_stats.ignored_count` | The number of the employee's credentials in the `ignored` state (Ignored Credential Count). |
| `state_stats.false_positive_count` | The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count). |
| `risk_score` | The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk. |

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `email` | The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited. |
| `domain` | The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain. |
| `first_name` | The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `last_name` | The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `title` | The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `linkedin_url` | The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `department` | The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `security_profile.composition.dominant_structure` | The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `is_executive` | Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint. |
| `security_profile.temporal.exposure_accelerating` | Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `computed_state` | The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`. |
| `risk_level` | The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`. |

### Sortable Fields

| Field | Description |
|---|---|
| `id` | The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`. |
| `email` | The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited. |
| `domain` | The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain. |
| `is_executive` | Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint. |
| `first_name` | The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `last_name` | The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `title` | The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `linkedin_url` | The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `department` | The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
| `security_profile.exposure.first_exposure_date` | When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time). |
| `security_profile.exposure.last_exposure_date` | When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first. |
| `security_profile.exposure.exposure_span_days` | The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day. |
| `security_profile.password_behavior.unique_password_count` | The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column. |
| `security_profile.password_behavior.avg_password_length` | The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH). |
| `security_profile.password_behavior.avg_strength_score` | The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10. |
| `security_profile.password_behavior.min_strength_score` | The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE). |
| `security_profile.password_behavior.max_strength_score` | The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE). |
| `security_profile.password_behavior.strength_distribution.very_weak` | The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.weak` | The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.medium` | The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.strong` | The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.strength_distribution.very_strong` | The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential. |
| `security_profile.password_behavior.weak_password_percentage` | The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS). |
| `security_profile.reuse_analysis.password_reuse_count` | The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS). |
| `security_profile.reuse_analysis.password_reuse_percentage` | The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column). |
| `security_profile.composition.common_password_count` | The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS. |
| `security_profile.composition.dictionary_word_count` | The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS. |
| `security_profile.composition.keyboard_pattern_count` | The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS. |
| `security_profile.composition.date_pattern_count` | The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS. |
| `security_profile.composition.avg_character_classes` | The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES). |
| `security_profile.composition.all_four_classes_percentage` | The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES). |
| `security_profile.composition.dominant_structure` | The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive. |
| `security_profile.composition.structure_variety_count` | The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY). |
| `security_profile.temporal.days_since_last_exposure` | The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST. |
| `security_profile.temporal.exposure_accelerating` | Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE. |
| `security_profile.temporal.exposure_velocity` | How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo). |
| `computed_state` | The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`. |
| `state_stats.total` | The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group). |
| `state_stats.active_count` | The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count). |
| `state_stats.inactive_count` | The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count). |
| `state_stats.unresolved_count` | The number of the employee's credentials that are unresolved (Unresolved Credential Count). |
| `state_stats.resolved_count` | The number of the employee's credentials that are resolved (Resolved Credential Count). |
| `state_stats.risk_accepted_count` | The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count). |
| `state_stats.ignored_count` | The number of the employee's credentials in the `ignored` state (Ignored Credential Count). |
| `state_stats.false_positive_count` | The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count). |
| `risk_score` | The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk. |
| `risk_level` | The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency. |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].email` | string |  |
| `results[].domain` | string |  |
| `results[].is_executive` | boolean |  |
| `results[].first_name` | string |  |
| `results[].last_name` | string |  |
| `results[].title` | string |  |
| `results[].linkedin_url` | string |  |
| `results[].department` | string |  |
| `results[].security_profile` | object |  |
| `results[].computed_state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `results[].state_stats` | object |  |
| `results[].risk_score` | integer |  |
| `results[].risk_level` | string | One of `low`, `medium`, `high`, `critical` |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].email` | string |
| `results[].domain` | string |
| `results[].is_executive` | boolean |
| `results[].first_name` | null |
| `results[].last_name` | null |
| `results[].title` | null |
| `results[].linkedin_url` | null |
| `results[].department` | null |
| `results[].security_profile` | object |
| `results[].security_profile.exposure` | object |
| `results[].security_profile.exposure.first_exposure_date` | string |
| `results[].security_profile.exposure.last_exposure_date` | string |
| `results[].security_profile.exposure.exposure_span_days` | number |
| `results[].security_profile.password_behavior` | object |
| `results[].security_profile.password_behavior.unique_password_count` | number |
| `results[].security_profile.password_behavior.avg_password_length` | number |
| `results[].security_profile.password_behavior.avg_strength_score` | number |
| `results[].security_profile.password_behavior.min_strength_score` | number |
| `results[].security_profile.password_behavior.max_strength_score` | number |
| `results[].security_profile.password_behavior.strength_distribution` | object |
| `results[].security_profile.password_behavior.strength_distribution.very_weak` | number |
| `results[].security_profile.password_behavior.strength_distribution.weak` | number |
| `results[].security_profile.password_behavior.strength_distribution.medium` | number |
| `results[].security_profile.password_behavior.strength_distribution.strong` | number |
| `results[].security_profile.password_behavior.strength_distribution.very_strong` | number |
| `results[].security_profile.password_behavior.weak_password_percentage` | number |
| `results[].security_profile.reuse_analysis` | object |
| `results[].security_profile.reuse_analysis.password_reuse_count` | number |
| `results[].security_profile.reuse_analysis.password_reuse_percentage` | number |
| `results[].security_profile.composition` | object |
| `results[].security_profile.composition.common_password_count` | number |
| `results[].security_profile.composition.dictionary_word_count` | number |
| `results[].security_profile.composition.keyboard_pattern_count` | number |
| `results[].security_profile.composition.date_pattern_count` | number |
| `results[].security_profile.composition.avg_character_classes` | number |
| `results[].security_profile.composition.all_four_classes_percentage` | number |
| `results[].security_profile.composition.dominant_structure` | string |
| `results[].security_profile.composition.structure_variety_count` | number |
| `results[].security_profile.temporal` | object |
| `results[].security_profile.temporal.credential_timeline` | array<object> |
| `results[].security_profile.temporal.credential_timeline[].year` | number |
| `results[].security_profile.temporal.credential_timeline[].month` | number |
| `results[].security_profile.temporal.credential_timeline[].count` | number |
| `results[].security_profile.temporal.exposure_velocity` | number |
| `results[].security_profile.temporal.exposure_accelerating` | boolean |
| `results[].security_profile.temporal.days_since_last_exposure` | number |
| `results[].computed_state` | string |
| `results[].state_stats` | object |
| `results[].state_stats.total` | number |
| `results[].state_stats.active_count` | number |
| `results[].state_stats.inactive_count` | number |
| `results[].state_stats.unresolved_count` | number |
| `results[].state_stats.resolved_count` | number |
| `results[].state_stats.risk_accepted_count` | number |
| `results[].state_stats.ignored_count` | number |
| `results[].state_stats.false_positive_count` | number |
| `results[].risk_score` | number |
| `results[].risk_level` | string |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-accounts/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000ec9430001",
      "email": "user@acme.example",
      "domain": "acme.example",
      "is_executive": false,
      "first_name": null,
      "last_name": null,
      "title": null,
      "linkedin_url": null,
      "department": null,
      "security_profile": {
        "exposure": {
          "first_exposure_date": "2025-06-01T08:00:00Z",
          "last_exposure_date": "2025-07-31T08:00:00Z",
          "exposure_span_days": 60
        },
        "password_behavior": {
          "unique_password_count": 3,
          "avg_password_length": 9,
          "avg_strength_score": 44,
          "min_strength_score": 25,
          "max_strength_score": 62,
          "strength_distribution": {
            "very_weak": 1,
            "weak": 1,
            "medium": 1,
            "strong": 0,
            "very_strong": 0
          },
          "weak_password_percentage": 67
        },
        "reuse_analysis": {
          "password_reuse_count": 1,
          "password_reuse_percentage": 33
        },
        "composition": {
          "common_password_count": 0,
          "dictionary_word_count": 0,
          "keyboard_pattern_count": 0,
          "date_pattern_count": 0,
          "avg_character_classes": 3,
          "all_four_classes_percentage": 50,
          "dominant_structure": "********",
          "structure_variety_count": 1
        },
        "temporal": {
          "credential_timeline": [
            {
              "year": 2025,
              "month": 6,
              "count": 10
            },
            {
              "year": 2025,
              "month": 7,
              "count": 11
            }
          ],
          "exposure_velocity": 0.5,
          "exposure_accelerating": false,
          "days_since_last_exposure": 30
        }
      },
      "computed_state": "unresolved",
      "state_stats": {
        "total": 36,
        "active_count": 9,
        "inactive_count": 36,
        "unresolved_count": 22,
        "resolved_count": 28,
        "risk_accepted_count": 6,
        "ignored_count": 17,
        "false_positive_count": 35
      },
      "risk_score": 20,
      "risk_level": "low"
    },
    {
      "id": "000000000000000ec9430002",
      "email": "user@fernhill.example",
      "domain": "fernhill.example",
      "is_executive": false,
      "first_name": null,
      "last_name": null,
      "title": null,
      "linkedin_url": null,
      "department": null,
      "security_profile": {
        "exposure": {
          "first_exposure_date": "2025-05-25T08:00:00Z",
          "last_exposure_date": "2025-07-24T08:00:00Z",
          "exposure_span_days": 60
        },
        "password_behavior": {
          "unique_password_count": 3,
          "avg_password_length": 9,
          "avg_strength_score": 44,
          "min_strength_score": 25,
          "max_strength_score": 62,
          "strength_distribution": {
            "very_weak": 1,
            "weak": 1,
            "medium": 1,
            "strong": 0,
            "very_strong": 0
          },
          "weak_password_percentage": 67
        },
        "reuse_analysis": {
          "password_reuse_count": 1,
          "password_reuse_percentage": 33
        },
        "composition": {
          "common_password_count": 0,
          "dictionary_word_count": 0,
          "keyboard_pattern_count": 0,
          "date_pattern_count": 0,
          "avg_character_classes": 3,
          "all_four_classes_percentage": 50,
          "dominant_structure": "********",
          "structure_variety_count": 1
        },
        "temporal": {
          "credential_timeline": [
            {
              "year": 2025,
              "month": 9,
              "count": 13
            },
            {
              "year": 2025,
              "month": 10,
              "count": 14
            }
          ],
          "exposure_velocity": 0.5,
          "exposure_accelerating": false,
          "days_since_last_exposure": 30
        }
      },
      "computed_state": "unresolved",
      "state_stats": {
        "total": 37,
        "active_count": 10,
        "inactive_count": 37,
        "unresolved_count": 23,
        "resolved_count": 29,
        "risk_accepted_count": 7,
        "ignored_count": 18,
        "false_positive_count": 36
      },
      "risk_score": 21,
      "risk_level": "low"
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-accounts/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-accounts/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "security_profile.exposure.first_exposure_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "security_profile.exposure.last_exposure_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "security_profile.exposure.exposure_span_days",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.unique_password_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.avg_password_length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.avg_strength_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.min_strength_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.max_strength_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.strength_distribution.very_weak",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.strength_distribution.weak",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.strength_distribution.medium",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.strength_distribution.strong",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.strength_distribution.very_strong",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.password_behavior.weak_password_percentage",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.reuse_analysis.password_reuse_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.reuse_analysis.password_reuse_percentage",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.common_password_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.dictionary_word_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.keyboard_pattern_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.date_pattern_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.avg_character_classes",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.all_four_classes_percentage",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.composition.structure_variety_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.temporal.days_since_last_exposure",
        "type": "eq",
        "value": 0
      },
      {
        "name": "security_profile.temporal.exposure_velocity",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.total",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.active_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.inactive_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.unresolved_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.resolved_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.risk_accepted_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.ignored_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "state_stats.false_positive_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "risk_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "first_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "last_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "title",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "linkedin_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "department",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "security_profile.composition.dominant_structure",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "is_executive",
        "type": "eq",
        "value": true
      },
      {
        "name": "security_profile.temporal.exposure_accelerating",
        "type": "eq",
        "value": true
      },
      {
        "name": "computed_state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "risk_level",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```
