Skip to main content
Home > MyID Product Family > MyID PSM > MyID Password Breach Data

MyID Password
Breach Data

11 billion plus compromised credentials, many recovered to clear text, maintained by Intercede's security team. Available by API or as a local copy of the database, ready to drop into your own service. Protect your customers from account takeover and the reputational damage that follows.

Database API

11 billion plus credentials, updated continuously.

Millions of compromised usernames and passwords appear on the dark web every day. Service providers need current, comprehensive intelligence to protect their customers. MyID® Password Breach Data is the same dataset that powers MyID PSM. Use it to check passwords against known breaches in line with NIST SP 800-63B, with two delivery options to fit your operating model.

Option 1

Database API

Intercede holds the data. Your service queries it via a simple API. No copy lands in your infrastructure.
  • Always-current intelligence, no synchronisation overhead
  • Aligns with NIST SP 800-63B best practice
  • Best for those who prefer to keep password data outside their systems
Option 2

Local Copy of Database

Download the breach database into your own environment, with regular updates. Your service runs the checks locally.
  • Regular updates pulled into your infrastructure
  • Aligns with NIST SP 800-63B best practice
  • Best for those who need full control of breach data inside their own perimeter
More than just breach checking

Real-time intelligence, in depth.

The breach data goes further than reporting incidents. Each record carries the context security teams need: hashing algorithms, plain-text recovery rate, total accounts affected, verification status and the breach origin. Fully compliant with legal and ethical standards.

Real-time data

Updated continuously from trusted, publicly-disclosed incidents. The intelligence is current the moment your service queries it.

Hashing context

Each record carries the password hashing algorithm used in the original breach, plus the recovery rate for plain-text recovery from those hashes.

Verification status

Breach records are verified before publication. Your service treats verified intelligence as actionable; unverified records are flagged.

Accounts affected

Total accounts compromised by each breach, so your service can weight risk by impact, not just match-counts.

Data origin

Each record carries its origin, the breach name, dataset and disclosure context, so you can show provenance in your own reporting.

Legal compliance

All data acquired and processed in line with legal and ethical standards. Your customers can rely on the provenance of the intelligence they receive.

Premium intelligence

Domain prioritisation and password hashing

For service providers who need more than the standard breach feed, the premium tier focuses analyst effort on your customers' specific exposure.

Domain prioritisation

Premium customers can have analyst search effort prioritised on credentials linked to their enterprise domain, with password hash cracking focused on those domains too.

Password hashing

Compromised passwords aren't always stored as plain text. Intercede's team of ethical hackers carries the expertise in password hashing methods and the techniques used to crack them, the same techniques bad actors use on the dark web.

Frequently Asked Questions

Common questions

Everything you need to know. Can't find the answer? Contact our team →

Service providers, software vendors and security products that need to check passwords against breach intelligence inside their own service. If you run your own servers and want to add breach checking without building the dataset yourself, this is for you.

Intercede continuously add newly-compromised credentials from monitored breach sources. The API serves the current dataset.

MyID PSM is a complete password security product for enterprises: policy engine, Domain Controller Agent, real-time enforcement. Password Breach Data is the breach intelligence layer on its own, packaged for service providers who want to embed it in their own products. Same underlying database.

Yes. All data is acquired and processed in line with legal and ethical standards. We document provenance for every record so your customers can see where the intelligence comes from.

MyID Password Breach Data

Want to know more?

Tell us about your service and we'll match you to the right delivery option, API or local copy, with the right tier of analyst support.