# Email Breach List

GET /cti/email-breaches/breaches: Lists breaches that include your email addresses. Filter and sort with the optional query parameters.

Source: https://docs.deepinfo.com/reference/cti/email-breach-list/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/email-breaches/breaches`

Lists breaches that include your email addresses. Filter and sort with the optional query parameters.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `ordering` | Optional |  |  |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |
| `title__contains` | Optional |  |  |
| `title__not_contains` | Optional |  |  |
| `domain__contains` | Optional |  |  |
| `domain__not_contains` | Optional |  |  |
| `breach_date__lt` | Optional |  |  |
| `breach_date__gt` | Optional |  |  |
| `added_date__lt` | Optional |  |  |
| `added_date__gt` | Optional |  |  |
| `total_breached_account_count__lt` | Optional |  |  |
| `total_breached_account_count__gt` | Optional |  |  |
| `data_types__in` | Optional |  |  |
| `data_types__nin` | Optional |  |  |
| `is_verified` | Optional |  |  |
| `is_fabricated` | Optional |  |  |
| `is_sensitive` | Optional |  |  |
| `is_retired` | Optional |  |  |
| `is_spam_list` | Optional |  |  |
| `is_malware` | Optional |  |  |
| `breached_account` | Optional |  |  |
| `breached_account__contains` | Optional |  |  |
| `breached_account__not_contains` | Optional |  |  |
| `breached_account_count__lt` | Optional |  |  |
| `breached_account_count__gt` | Optional |  |  |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].name` | string |  |
| `results[].title` | string |  |
| `results[].domain` | string |  |
| `results[].breach_date` | string | date-time |
| `results[].added_date` | string | date-time |
| `results[].modified_date` | string | date-time |
| `results[].total_breached_account_count` | integer |  |
| `results[].logo_path` | string |  |
| `results[].data_types` | array of string |  |
| `results[].is_verified` | boolean |  |
| `results[].is_fabricated` | boolean |  |
| `results[].is_sensitive` | boolean |  |
| `results[].is_retired` | boolean |  |
| `results[].is_spam_list` | boolean |  |
| `results[].is_malware` | boolean |  |
| `results[].is_subscription_free` | boolean |  |
| `results[].breached_account_count` | integer |  |
| `results[].breached_domains` | array of object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].name` | string |
| `results[].title` | string |
| `results[].domain` | string |
| `results[].breach_date` | string |
| `results[].added_date` | string |
| `results[].modified_date` | string |
| `results[].total_breached_account_count` | number |
| `results[].logo_path` | string |
| `results[].data_types` | array<string> |
| `results[].is_verified` | boolean |
| `results[].is_fabricated` | boolean |
| `results[].is_sensitive` | boolean |
| `results[].is_retired` | boolean |
| `results[].is_spam_list` | boolean |
| `results[].is_malware` | boolean |
| `results[].is_subscription_free` | boolean |
| `results[].breached_account_count` | number |
| `results[].breached_domains` | array<object> |
| `results[].breached_domains[].domain` | string |
| `results[].breached_domains[].favicon` | null |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/cti/email-breaches/breaches?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "acme-breach",
      "name": "Fernhill Forum",
      "title": "Fernhill Forum",
      "domain": "acme.example",
      "breach_date": "2025-06-01T08:00:00Z",
      "added_date": "2025-06-01T08:00:00Z",
      "modified_date": "2025-07-01T08:00:00Z",
      "total_breached_account_count": 30,
      "logo_path": "https://platform-storage.example/logos/acme.png",
      "data_types": [
        "Email addresses",
        "Passwords"
      ],
      "is_verified": true,
      "is_fabricated": false,
      "is_sensitive": false,
      "is_retired": false,
      "is_spam_list": false,
      "is_malware": false,
      "is_subscription_free": true,
      "breached_account_count": 29,
      "breached_domains": [
        {
          "domain": "acme.example",
          "favicon": null
        },
        {
          "domain": "fernhill.example",
          "favicon": null
        }
      ]
    },
    {
      "id": "acme-breach-2",
      "name": "Kestrel Travel",
      "title": "Kestrel Travel",
      "domain": "fernhill.example",
      "breach_date": "2025-05-25T08:00:00Z",
      "added_date": "2025-05-25T08:00:00Z",
      "modified_date": "2025-06-24T08:00:00Z",
      "total_breached_account_count": 31,
      "logo_path": "https://platform-storage.example/logos/acme-2.png",
      "data_types": [
        "Names",
        "Phone numbers"
      ],
      "is_verified": true,
      "is_fabricated": false,
      "is_sensitive": false,
      "is_retired": false,
      "is_spam_list": false,
      "is_malware": false,
      "is_subscription_free": true,
      "breached_account_count": 30,
      "breached_domains": [
        {
          "domain": "acme.example",
          "favicon": null
        }
      ]
    }
  ]
}
```

### 400 · Invalid Parameter (invalid breached_account_count__gt=abc)

```bash
curl 'https://api.deepinfo.com/v1/cti/email-breaches/breaches?breached_account_count__gt=abc' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "breached_account_count__gt",
      "details": [
        "A valid integer is required."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
