Retrieve full exposure history for specific email addresses, usernames, or credential hashes.
What this endpoint does
Looks up compromised credentials for specific identities across all breach dumps and stealer malware logs in Identity Intelligence. Identities can be specified as email addresses (subjects), SHA1-hashed email addresses for privacy-preserving queries (subjects_sha1), or domain-and-username pairs (subjects_login). Multiple identities can be queried in a single request. Use the Identity: Search endpoint for broader queries when you don't have specific identities, or the Identity: Detections endpoint to monitor an entire domain for new exposures.
Response data
Returns identities grouped by subject, each containing credential records with breach source metadata (dump name, download date, and optionally compromise details for malware-sourced data), password hash values and complexity indicators, the targeted authorization service (login URL and domain), and when sourced from stealer malware logs, the responsible malware family and stolen browser cookies.
