# Breaches > An index and topic collection covering data breach intelligence, credential exposure databases, dark-web monitoring, and leak detection APIs. Breach intelligence platforms aggregate compromised credentials, stealer logs, ransomware leak-site posts, underground forum chatter, and dark-web marketpl... This is the **Breaches** topic area of [API Evangelist](https://apievangelist.com) — a network of focused knowledge bases drawn from 16 years of independent API research by Kin Lane. Browse all areas at https://apievangelist.com/areas/. ## Services & Tools - [Have I Been Pwned](https://providers.apis.io/providers/have-i-been-pwned/) (repo: https://github.com/api-evangelist/have-i-been-pwned) - [CrowdStrike](https://providers.apis.io/providers/crowdstrike/) (repo: https://github.com/api-evangelist/crowdstrike) - [Microsoft Defender](https://providers.apis.io/providers/microsoft-defender/) (repo: https://github.com/api-evangelist/microsoft-defender) - [Microsoft Defender for Cloud](https://providers.apis.io/providers/microsoft-defender-for-cloud/) (repo: https://github.com/api-evangelist/microsoft-defender-for-cloud) - [Microsoft Sentinel](https://providers.apis.io/providers/microsoft-sentinel/) (repo: https://github.com/api-evangelist/microsoft-sentinel) - [Microsoft Graph](https://providers.apis.io/providers/microsoft-graph/) (repo: https://github.com/api-evangelist/microsoft-graph) - [SentinelOne](https://providers.apis.io/providers/sentinelone/) (repo: https://github.com/api-evangelist/sentinelone) - [Sophos](https://providers.apis.io/providers/sophos/) (repo: https://github.com/api-evangelist/sophos) - [Symantec](https://providers.apis.io/providers/symantec/) (repo: https://github.com/api-evangelist/symantec) - [Trellix](https://providers.apis.io/providers/trellix/) (repo: https://github.com/api-evangelist/trellix) - [McAfee](https://providers.apis.io/providers/mcafee/) (repo: https://github.com/api-evangelist/mcafee) - [Splunk](https://providers.apis.io/providers/splunk/) (repo: https://github.com/api-evangelist/splunk) - [Amazon Detective](https://providers.apis.io/providers/amazon-detective/) (repo: https://github.com/api-evangelist/amazon-detective) - [Amazon GuardDuty](https://providers.apis.io/providers/amazon-guardduty/) (repo: https://github.com/api-evangelist/amazon-guardduty) - [Amazon Macie](https://providers.apis.io/providers/amazon-macie/) (repo: https://github.com/api-evangelist/amazon-macie) - [Google Cloud Security Command Center](https://providers.apis.io/providers/google-cloud-security-command-center/) (repo: https://github.com/api-evangelist/google-cloud-security-command-center) - [Google Safe Browsing](https://providers.apis.io/providers/google-safe-browsing/) (repo: https://github.com/api-evangelist/google-safe-browsing) - [Qualys](https://providers.apis.io/providers/qualys/) (repo: https://github.com/api-evangelist/qualys) - [Rapid7](https://providers.apis.io/providers/rapid7/) (repo: https://github.com/api-evangelist/rapid7) - [Tanium](https://providers.apis.io/providers/tanium/) (repo: https://github.com/api-evangelist/tanium) - [Sumo Logic](https://providers.apis.io/providers/sumo-logic/) (repo: https://github.com/api-evangelist/sumo-logic) - [Cloudflare](https://providers.apis.io/providers/cloudflare-com/) (repo: https://github.com/api-evangelist/cloudflare-com) - [Fortinet](https://providers.apis.io/providers/fortinet/) (repo: https://github.com/api-evangelist/fortinet) - [Check Point](https://providers.apis.io/providers/check-point/) (repo: https://github.com/api-evangelist/check-point) - [Palo Alto Networks](https://providers.apis.io/providers/palo-alto-networks/) (repo: https://github.com/api-evangelist/palo-alto-networks) - [BeyondTrust](https://providers.apis.io/providers/beyondtrust/) (repo: https://github.com/api-evangelist/beyondtrust) - [CyberArk](https://providers.apis.io/providers/cyberark/) (repo: https://github.com/api-evangelist/cyberark) - [Okta](https://providers.apis.io/providers/okta/) (repo: https://github.com/api-evangelist/okta) - [Auth0](https://providers.apis.io/providers/auth0/) (repo: https://github.com/api-evangelist/auth0) - [1Password](https://providers.apis.io/providers/1password/) (repo: https://github.com/api-evangelist/1password) - [LastPass](https://providers.apis.io/providers/lastpass/) (repo: https://github.com/api-evangelist/lastpass) - [Bitwarden](https://providers.apis.io/providers/bitwarden/) (repo: https://github.com/api-evangelist/bitwarden) - [NVD](https://providers.apis.io/providers/nvd/) (repo: https://github.com/api-evangelist/nvd) - [Cybersecurity and Infrastructure Security Agency](https://providers.apis.io/providers/cybersecurity-and-infrastructure-security-agency/) (repo: https://github.com/api-evangelist/cybersecurity-and-infrastructure-security-agency) - [Federal Trade Commission](https://providers.apis.io/providers/federal-trade-commission/) (repo: https://github.com/api-evangelist/federal-trade-commission) - [NIST](https://providers.apis.io/providers/nist/) (repo: https://github.com/api-evangelist/nist) - [Varonis](https://providers.apis.io/providers/varonis/) (repo: https://github.com/api-evangelist/varonis) - [Zscaler](https://providers.apis.io/providers/zscaler/) (repo: https://github.com/api-evangelist/zscaler) ## Common Features - **Email and Account Breach Lookup**: APIs like Have I Been Pwned let consumers and security teams check whether an email address, username, or phone number has appeared in known data breaches and stealer log corpora. - **Pwned Password Checking (K-Anonymity)**: The Pwned Passwords API exposes 800+ million breached password hashes through a k-anonymity protocol, letting applications block known-compromised credentials without transmitting full hashes. - **Dark Web and Underground Forum Monitoring**: Enterprise breach intelligence platforms continuously scrape dark-web marketplaces, ransomware leak sites, Telegram channels, and underground forums for mentions of customer data, executives, brands, and credentials. - **Stealer Log and Credential Exposure Feeds**: Modern breach intelligence increasingly centers on infostealer malware logs (RedLine, Raccoon, Vidar, LummaC2) that capture browser-stored credentials, session cookies, and crypto wallets at scale. - **Ransomware Leak-Site Tracking**: Threat intelligence APIs track ransomware group leak sites (LockBit, Cl0p, ALPHV, Akira) to surface newly disclosed victim organizations and stolen data postings as they appear. - **Vulnerability and Exposure Feeds**: Authoritative vulnerability databases (NVD, CISA KEV) and commercial exposure platforms (Qualys, Rapid7, Tanium) expose CVE, CVSS, and known-exploited-vulnerability metadata via API. - **Regulatory Breach Notification Feeds**: Government authorities (FTC, state AGs, EU DPAs, HHS) publish disclosed breach filings; security teams ingest these feeds to track third-party and supply-chain breach exposure. - **Credential Stuffing Defense**: Identity providers (Okta, Auth0) and password managers (1Password, Bitwarden, LastPass) integrate with breach feeds to block re-use of known-compromised passwords and force resets on exposed accounts. ## Use Cases - **Employee Credential Exposure Monitoring**: Security teams continuously query breach intelligence APIs for corporate email domains to detect employee credentials exposed in third-party breaches and infostealer logs, triggering forced password resets. - **Customer Account Takeover Prevention**: Consumer applications integrate Pwned Passwords and breach lookup APIs at signup and login to block known-compromised credentials and notify customers of exposure. - **Executive and VIP Protection**: Brand and executive protection teams use dark-web monitoring APIs to detect doxxing, leaked personal data, and impersonation targeting C-suite, board members, and high-value employees. - **Third-Party and Supply-Chain Risk**: GRC teams ingest breach-notification feeds and regulatory disclosures via API to track breach incidents at vendors, suppliers, and partners that handle their data. - **Ransomware Victim Intelligence**: Threat intel teams subscribe to ransomware leak-site feeds via API to alert on newly named victims relevant to their industry, supply chain, or geography. - **Vulnerability Prioritization**: Vulnerability management teams combine NVD CVE data, CISA's Known Exploited Vulnerabilities (KEV) catalog, and commercial exposure platforms to prioritize patching based on breach exploitation evidence. - **Regulatory Breach Disclosure Compliance**: Privacy and legal teams query FTC, state AG, and EU DPA breach-notification APIs to track required disclosures and benchmark their own incident response. - **AI Agent Breach Triage**: AI agents wired to breach intelligence APIs autonomously enrich security alerts with exposure context, correlate stolen credentials with active sessions, and draft incident-response runbooks. ## Related Areas - [Visualization](https://visualization.apievangelist.com): An index and topic collection covering data visualization, charts, dashboards, business intelligence (BI), and report... - [Privacy](https://privacy.apievangelist.com): An index and topic collection covering privacy management, consent management, data subject rights, data classificati... - [Performance](https://performance.apievangelist.com): An index and topic collection covering API and web performance, including load testing, performance benchmarking, rea... - [Scraping](https://scraping.apievangelist.com): An index and topic collection covering web scraping platforms, proxy networks, SERP APIs, browser-based extraction se... - [Observability](https://observability.apievangelist.com): A curated index of services, tooling, and open source solutions for API observability, monitoring, logging, tracing, ... - [Monitoring](https://monitoring.apievangelist.com): An index and topic collection covering API monitoring, application performance monitoring, observability, uptime moni... ## More - [Latest Breaches stories](/stories/) - [All API Evangelist topic areas](https://apievangelist.com/areas/) - [API Evangelist network index (llms.txt)](https://apievangelist.com/llms.txt)