The Data Breaches API turns compromised credential data into structured JSON - accounts exposed in data breaches, combo lists, and infostealer logs, collected continuously and enriched for threat intelligence.
Records come from two kinds of sources, exposed in the type field:
data_breach) - large-scale leaks and dumps from breached services and combo lists.infostealer) - credentials and device data harvested from malware-infected machines.The sub_type field narrows this further: database_dump, data_breach_combo_list, stealer_logs, stealers_combo_list.
Every record is enriched at collection time:
VPN and name Fortinet, derived from the login URL.next URL to page through the rest - see Pagination.The Data Breaches API requires its own permission and authorized domains on your account. You can only search domains authorized for your token - contact [email protected] for access.