Satanic is a cybercrime-forum persona associated with the publication and sale of purportedly stolen databases. In August 2026, the actor released a dataset claimed to contain information from hundreds of Stripe-using merchants, including customer and invoice records, transaction metadata, promotional codes, and live Stripe API keys. The actor claimed to hold a substantially larger collection of payment-platform API keys and indicated that additional data would be released. Exposure of such credentials could permit programmatic access to merchant payment environments and enable access to customer information, unauthorized refunds, payment-routing changes, or account-setting modifications, subject to key permissions. Satanic has also advertised alleged databases attributed to commercial organizations, but the underlying intrusion claims and acquisition methods have not been independently confirmed. The actor's activity is consistent with financially motivated data theft and monetization through cybercrime forums.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Posted an alleged archive containing data from hundreds of Stripe merchants and associated account access keys. The content explicitly says it is unclear whether this incident was connected to the breaches of Davayte and You Are Not Alone.
Advertising the alleged sale of a stolen Wrappiness.co customer database containing millions of records and administrator account data on a breach forum.
Published leaked Stripe-related vendor data on pwnforums, claimed possession of approximately 20,000 compromised Stripe API keys, and threatened staggered releases of additional data.
Published leaked data allegedly extracted from hundreds of Stripe-using vendors, including compromised API keys, customer records, invoices, and promotional codes, and claimed to possess a much larger cache for staggered release.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.