# Email Breach Detail

GET /cti/email-breaches/breaches/{breach_id}: Returns one breach: date, description, data types and affected accounts count.

Source: https://docs.deepinfo.com/reference/cti/email-breach-detail/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/email-breaches/breaches/{breach_id}`

Returns one breach: date, description, data types and affected accounts count.

## Authentication

Send your API key in the `apikey` request header.

## Path Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `breach_id` | Required |  | `acme-breach` |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `id` | string |  |
| `name` | string |  |
| `title` | string |  |
| `domain` | string |  |
| `breach_date` | string | date-time |
| `added_date` | string | date-time |
| `modified_date` | string | date-time |
| `total_breached_account_count` | integer |  |
| `description` | string |  |
| `logo_path` | string |  |
| `data_types` | array of string |  |
| `is_verified` | boolean |  |
| `is_fabricated` | boolean |  |
| `is_sensitive` | boolean |  |
| `is_retired` | boolean |  |
| `is_spam_list` | boolean |  |
| `is_malware` | boolean |  |
| `is_subscription_free` | boolean |  |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `id` | string |
| `name` | string |
| `title` | string |
| `domain` | string |
| `breach_date` | string |
| `added_date` | string |
| `modified_date` | string |
| `total_breached_account_count` | number |
| `description` | string |
| `logo_path` | string |
| `data_types` | array<string> |
| `is_verified` | boolean |
| `is_fabricated` | boolean |
| `is_sensitive` | boolean |
| `is_retired` | boolean |
| `is_spam_list` | boolean |
| `is_malware` | boolean |
| `is_subscription_free` | boolean |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/cti/email-breaches/breaches/acme-breach' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "id": "acme-breach",
  "name": "Fernhill Forum",
  "title": "Fernhill Forum",
  "domain": "acme.example",
  "breach_date": "2025-06-01T08:00:00Z",
  "added_date": "2025-06-01T08:00:00Z",
  "modified_date": "2025-07-01T08:00:00Z",
  "total_breached_account_count": 29,
  "description": "A breach of an online service's user database.",
  "logo_path": "https://platform-storage.example/logos/acme.png",
  "data_types": [
    "Email addresses",
    "Passwords"
  ],
  "is_verified": true,
  "is_fabricated": false,
  "is_sensitive": false,
  "is_retired": false,
  "is_spam_list": false,
  "is_malware": false,
  "is_subscription_free": true
}
```

### 404 · Not Found (nonexistent breach_id)

```bash
curl 'https://api.deepinfo.com/v1/cti/email-breaches/breaches/ffffffffffffffffffffffff' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 30003,
  "details": [
    "Breach does not exist."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
