# Threat Actor Detail

GET /cti/threat-actors/{threat_actor_id}: Returns one threat actor profile.

Source: https://docs.deepinfo.com/reference/cti/threat-actor-detail/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/cti/threat-actors/{threat_actor_id}`

Returns one threat actor profile.

## Authentication

Send your API key in the `apikey` request header.

## Path Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `threat_actor_id` | Required |  | `<threat_actor_id>` |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `id` | string |  |
| `name` | string |  |
| `aliases` | array of string |  |
| `date_updated` | string | date-time |
| `date_first_seen` | string | date-time |
| `date_last_seen` | string | date-time |
| `is_active` | boolean |  |
| `actor_size` | string |  |
| `actor_types` | array of string |  |
| `actor_sophistication` | string |  |
| `actor_specializations` | array of string |  |
| `description` | string |  |
| `law_enforcement` | string |  |
| `contact_info` | object |  |
| `social_media` | object |  |
| `websites` | array of string |  |
| `payment_info` | object |  |
| `origin_countries` | array of string |  |
| `leak_names` | array of string |  |
| `forum_names` | array of string |  |
| `market_names` | array of string |  |
| `forum_market_usernames` | array of string |  |
| `targeted_regions` | array of string |  |
| `targeted_countries` | array of string |  |
| `targeted_industries` | array of string |  |
| `targeted_organizations` | array of string |  |
| `cves_used` | array of string |  |
| `tools_used` | array of string |  |

> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above.

## Examples

### 404 · Not Found (nonexistent threat_actor_id)

```bash
curl 'https://api.deepinfo.com/v1/cti/threat-actors/ffffffffffffffffffffffff' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 30003,
  "details": [
    "Threat Actor with given id=ffffffffffffffffffffffff does not exist."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
