Payments & Fintech
Stripe

API keys from 659 Stripe merchants leaked, exposing 688K customer records

A hacker going by “Satanic” posted a trove of stolen data on PwnForums on August 18, claiming to have exfiltrated live API keys from roughly 659 merchants who use Stripe for payment processing. The haul:. . .
cryptobriefing.com
August 24, 2026
5
Editorial Team
API keys from 659 Stripe merchants leaked, exposing 688K customer records
WHAT HAPPENED
A hacker going by “Satanic” posted a trove of stolen data on PwnForums on August 18, claiming to have exfiltrated live API keys from roughly 659 merchants who use Stripe for payment processing. The haul: approximately 688,363 customer records spanning 42 countries, totaling somewhere between 33 and 35 gigabytes of sensitive payment and customer data. The keys were harvested from the merchants themselves, pulled from public code repositories, infostealer malware, and misconfigured servers. How 50,000 keys ended up in the open The scale of the exposure goes well beyond the 659 merchants named in this particular dump. Investigations have found that over 50,000 Stripe API keys have been exposed in public domains, including GitHub Actions logs and web servers with broken access controls.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY