11 billion plus credentials, updated continuously.
Millions of compromised usernames and passwords appear on the dark web every day. Service providers need current, comprehensive intelligence to protect their customers. MyID® Password Breach Data is the same dataset that powers MyID PSM. Use it to check passwords against known breaches in line with NIST SP 800-63B, with two delivery options to fit your operating model.
Database API
- •Always-current intelligence, no synchronisation overhead
- •Aligns with NIST SP 800-63B best practice
- •Best for those who prefer to keep password data outside their systems
Local Copy of Database
- •Regular updates pulled into your infrastructure
- •Aligns with NIST SP 800-63B best practice
- •Best for those who need full control of breach data inside their own perimeter
Real-time intelligence, in depth.
The breach data goes further than reporting incidents. Each record carries the context security teams need: hashing algorithms, plain-text recovery rate, total accounts affected, verification status and the breach origin. Fully compliant with legal and ethical standards.
Real-time data
Updated continuously from trusted, publicly-disclosed incidents. The intelligence is current the moment your service queries it.
Hashing context
Each record carries the password hashing algorithm used in the original breach, plus the recovery rate for plain-text recovery from those hashes.
Verification status
Breach records are verified before publication. Your service treats verified intelligence as actionable; unverified records are flagged.
Accounts affected
Total accounts compromised by each breach, so your service can weight risk by impact, not just match-counts.
Data origin
Each record carries its origin, the breach name, dataset and disclosure context, so you can show provenance in your own reporting.
Legal compliance
All data acquired and processed in line with legal and ethical standards. Your customers can rely on the provenance of the intelligence they receive.
Domain prioritisation and password hashing
For service providers who need more than the standard breach feed, the premium tier focuses analyst effort on your customers' specific exposure.
Domain prioritisation
Premium customers can have analyst search effort prioritised on credentials linked to their enterprise domain, with password hash cracking focused on those domains too.
Password hashing
Compromised passwords aren't always stored as plain text. Intercede's team of ethical hackers carries the expertise in password hashing methods and the techniques used to crack them, the same techniques bad actors use on the dark web.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
Service providers, software vendors and security products that need to check passwords against breach intelligence inside their own service. If you run your own servers and want to add breach checking without building the dataset yourself, this is for you.
Intercede continuously add newly-compromised credentials from monitored breach sources. The API serves the current dataset.
MyID PSM is a complete password security product for enterprises: policy engine, Domain Controller Agent, real-time enforcement. Password Breach Data is the breach intelligence layer on its own, packaged for service providers who want to embed it in their own products. Same underlying database.
Yes. All data is acquired and processed in line with legal and ethical standards. We document provenance for every record so your customers can see where the intelligence comes from.
Want to know more?
Tell us about your service and we'll match you to the right delivery option, API or local copy, with the right tier of analyst support.