# Email Breach Stats

GET /cti/email-breaches/breaches/stats: Breach statistics.

Source: https://docs.deepinfo.com/reference/cti/email-breach-stats/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/email-breaches/breaches/stats`

Breach statistics.

## Authentication

Send your API key in the `apikey` request header.

## Response Fields

| Field | Type | Description |
|---|---|---|
| `breach_count` | integer |  |
| `breached_account_count` | integer |  |
| `last_breach_date` | string | date-time |
| `data_type_stats` | array of object |  |
| `timeline` | array of object |  |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `breach_count` | number |
| `breached_account_count` | number |
| `last_breach_date` | string |
| `data_type_stats` | array<object> |
| `data_type_stats[].affected_account_count` | number |
| `data_type_stats[].type` | string |
| `timeline` | array<object> |
| `timeline[].year` | number |
| `timeline[].breach_count` | number |
| `timeline[].breached_account_count` | number |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/cti/email-breaches/breaches/stats' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "breach_count": 8,
  "breached_account_count": 22,
  "last_breach_date": "2025-06-01T08:00:00Z",
  "data_type_stats": [
    {
      "affected_account_count": 2,
      "type": "Email addresses"
    },
    {
      "affected_account_count": 3,
      "type": "Passwords"
    }
  ],
  "timeline": [
    {
      "year": 2025,
      "breach_count": 38,
      "breached_account_count": 17
    },
    {
      "year": 2025,
      "breach_count": 39,
      "breached_account_count": 18
    }
  ]
}
```
