# Compromised Payment Credential Search

POST /cti/compromised-payment-credentials/search: Searches leaked payment cards and their state.

Source: https://docs.deepinfo.com/reference/cti/compromised-payment-credential-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-payment-credentials/search`

Searches leaked payment cards and their state.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "pan_last_four",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `pan` | The full card number (primary account number) found in the leak. Treat it as sensitive. |
| `pan_masked` | The card number in masked form, with part of the digits hidden. |
| `pan_last_four` | The last four digits of the card number. |
| `bin` | The card's bank identification number (BIN), the leading digits of the card number that identify the issuer. |
| `dedup_key` | A de-duplication key for the card record. |
| `card_brand` | The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`. |
| `card_type` | The card type: `credit`, `debit` or `prepaid`. |
| `card_level` | The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`. |
| `issuer_name` | The name of the card's issuer. |
| `issuer_country` | The country of the card's issuer. |
| `check_status` | The result of checking the card: `approved`, `declined` or `unknown`, which is the default. |
| `confidence` | The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE). |
| `leak_name` | The names of the leaks the card was found in, as a list. |
| `source_url` | The address of the source where the card was found. |
| `harvest_url` | The address the card record was harvested (collected) from, recorded separately from `source_url`. |
| `state` | The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `expiry_year` | The card's expiry year; it can be empty. |
| `expiry_month` | The card's expiry month, as a number; it can be empty. |
| `first_seen` | When the card was first seen (UTC date-time). |
| `last_seen` | When the card was last seen, shown as LAST SEEN (UTC date-time). |
| `times_seen` | How many times the card was seen (TIMES SEEN). |
| `hackishness` | The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results. |
| `co_listed_card_count` | The number of cards listed together with this card in its source. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `luhn_valid` | Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass. |
| `has_cvv` | Whether the leaked record includes the card's security code (CVV). |
| `is_validated_live` | Whether the card has been validated as live. |

Operators: not measured

| Field | Description |
|---|---|
| `source_format` | The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`. |
| `network` | Network names recorded for the card record, as a list of strings. |

### Sortable Fields

| Field | Description |
|---|---|
| `pan_last_four` | The last four digits of the card number. |
| `bin` | The card's bank identification number (BIN), the leading digits of the card number that identify the issuer. |
| `expiry_year` | The card's expiry year; it can be empty. |
| `card_brand` | The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`. |
| `issuer_country` | The country of the card's issuer. |
| `check_status` | The result of checking the card: `approved`, `declined` or `unknown`, which is the default. |
| `confidence` | The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE). |
| `source_format` | The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`. |
| `first_seen` | When the card was first seen (UTC date-time). |
| `last_seen` | When the card was last seen, shown as LAST SEEN (UTC date-time). |
| `times_seen` | How many times the card was seen (TIMES SEEN). |
| `hackishness` | The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results. |
| `co_listed_card_count` | The number of cards listed together with this card in its source. |
| `state` | The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].pan` | string |  |
| `results[].pan_masked` | string |  |
| `results[].pan_last_four` | string |  |
| `results[].bin` | string |  |
| `results[].dedup_key` | string |  |
| `results[].luhn_valid` | boolean |  |
| `results[].expiry_year` | integer |  |
| `results[].expiry_month` | integer |  |
| `results[].expiry_raw` | string |  |
| `results[].is_expired` | boolean |  |
| `results[].has_cvv` | boolean |  |
| `results[].card_brand` | string |  |
| `results[].card_type` | string |  |
| `results[].card_level` | string |  |
| `results[].issuer_name` | string |  |
| `results[].issuer_country` | string |  |
| `results[].check_status` | string |  |
| `results[].is_validated_live` | boolean |  |
| `results[].confidence` | string |  |
| `results[].source_format` | string |  |
| `results[].network` | array of string |  |
| `results[].leak_name` | array of string |  |
| `results[].source_url` | string |  |
| `results[].first_seen` | string | date-time |
| `results[].last_seen` | string | date-time |
| `results[].times_seen` | integer |  |
| `results[].hackishness` | number |  |
| `results[].harvest_url` | string |  |
| `results[].co_listed_card_count` | integer |  |
| `results[].other_context` | object |  |
| `results[].state` | string |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-payment-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 0,
  "results": []
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-payment-credentials/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-payment-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "pan",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "pan_masked",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "pan_last_four",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "bin",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dedup_key",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "card_brand",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "card_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "card_level",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "issuer_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "issuer_country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "check_status",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "confidence",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leak_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "source_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "harvest_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "expiry_year",
        "type": "eq",
        "value": 0
      },
      {
        "name": "expiry_month",
        "type": "eq",
        "value": 0
      },
      {
        "name": "first_seen",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_seen",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "times_seen",
        "type": "eq",
        "value": 0
      },
      {
        "name": "hackishness",
        "type": "eq",
        "value": 0
      },
      {
        "name": "co_listed_card_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "luhn_valid",
        "type": "eq",
        "value": true
      },
      {
        "name": "has_cvv",
        "type": "eq",
        "value": true
      },
      {
        "name": "is_validated_live",
        "type": "eq",
        "value": true
      }
    ]
  },
  "sort": [
    {
      "field": "pan_last_four",
      "order": "desc"
    }
  ]
}'
```
