# Compromised Employee Credential Stats

GET /cti/compromised-employee-credentials/stats: Compromised employee credential statistics.

Source: https://docs.deepinfo.com/reference/cti/compromised-employee-credential-stats/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/compromised-employee-credentials/stats`

Compromised employee credential statistics.

## Authentication

Send your API key in the `apikey` request header.

## Response Fields

| Field | Type | Description |
|---|---|---|
| `credential_count` | integer |  |
| `credential_account_count` | integer |  |
| `first_exposure_date` | string | date-time |
| `timeline` | array of object |  |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `credential_count` | number |
| `credential_account_count` | number |
| `first_exposure_date` | string |
| `timeline` | array<object> |
| `timeline[].year` | number |
| `timeline[].credential_count` | number |
| `timeline[].credential_account_count` | number |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/stats' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "credential_count": 11,
  "credential_account_count": 7,
  "first_exposure_date": "2025-06-01T08:00:00Z",
  "timeline": [
    {
      "year": 2025,
      "credential_count": 4,
      "credential_account_count": 37
    },
    {
      "year": 2025,
      "credential_count": 5,
      "credential_account_count": 38
    }
  ]
}
```
