A leaked dataset posted on an illicit forum exposed live Stripe API keys and related payment data from hundreds of merchants, with reports citing 659 to 669 vendor accounts, 1,033 confirmed keys in the initial release, and claims that the broader cache could contain up to 20,000 to 50,000 Stripe secrets. Researchers said the material included customer records, invoices, transaction metadata, hosted invoice links, promotional codes, partial payment card details, and roughly 33 GB to 35 GB of associated data, creating risks of fraud, privacy violations, unauthorized refunds, payment rerouting, and revenue loss.
Investigations indicate Stripe itself was not breached; instead, the exposed credentials appear to have been harvested from merchants’ public code repositories, unmasked GitHub Actions logs, misconfigured web servers, exposed environment files, or debug logs. Analysts verified that some sampled keys were still active and could be used to list customer data, create fraudulent payment links, modify webhooks, and even process test charges, while some merchants reportedly rotated keys without revoking old ones. Recommended response measures include auditing version-control history, revoking and rotating exposed keys, replacing broad secrets with restricted Stripe keys, and enabling Stripe fraud-detection controls such as Radar rules.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A dataset posted on a data-trading forum on August 18, 2026 contained live Stripe API keys for 659 merchant accounts along with roughly 35 GB of customer and payment data. The report said Stripe itself was not compromised because the exposed keys belonged to merchants rather than Stripe corporate systems.
Shortly after the initial release, Hudson Rock researchers communicated with Satanic, who said the published dump was only a fraction of the stolen data. The actor claimed to possess about 20,000 compromised Stripe API keys and threatened additional batch releases.
On August 18, 2026, threat actor Satanic published a Stripe-related data dump on the illicit forum pwnforums. The post claimed the leak involved hundreds of vendors, 1,033 API keys, and a much larger dataset than the downloadable archive provided.
After reviewing the leaked data, Hudson Rock said it found no infostealer infections tied to the affected vendor domains and judged that the incident likely did not stem from a single plugin or software suite. The analysis instead pointed to mass discovery of exposed environment files or debug logs, or compromise of shared infrastructure.
Researchers used an active leaked Stripe API key to access a merchant customer list, create a fraudulent payment link, and process a $1 test charge within 17 hours. The testing showed that exposed secret keys could still enable direct abuse when not revoked.
Ransomnews analyzed the leaked files offline and reported the exposure to Stripe before publishing its findings. Its testing found that some sampled leaked keys were still active.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourcehudsonrock.com
Open sourcesecurityaffairs.com
Open sourceransomnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.