Investing

API Keys From 659 Stripe Merchants Leaked Alongside 688,000…

API credentials tied to 659 merchants using Stripe have been leaked alongside approximately 35GB of customer and payment data covering 688,363 customer records across 42 countries, according to cybersecurity researchers investigating the dataset. The archive appeared on a data-trading forum on August 18 and was made available for free rather than offered through a ransom demand or conventional data sale. Researchers at Ransomnews analyzed the material offline and notified Stripe before publishing their findings.

Crucially, available evidence does not indicate that Stripe’s own infrastructure was compromised. Instead, the dataset appears to have been assembled using secret API credentials exposed by individual merchants and then querying Stripe through its legitimate application programming interfaces. The archive reportedly contains 17,654 files and includes customer objects, charges, payment intents, checkout sessions, invoices, payouts, refunds, disputes, subscriptions, products and pricing information. Records span from January 2022 through June 2026.

Hundreds of Keys Retained Payment and Payout Capabilities

Of the credentials associated with the 659 merchants, researchers identified 650 as live secret keys carrying Stripe’s sk_live prefix and another nine as restricted keys. Metadata included with the collection indicated that 573 affected merchant accounts could accept payments and 531 could make payouts. A total of 519 reportedly retained both capabilities. That makes the exposure substantially more serious than the compromise of ordinary account passwords.

Stripe secret API keys provide programmatic access to merchant functions. Depending on permissions and account configuration, possession of a valid key can potentially allow an attacker to retrieve customer information, create payment intents or charges, issue refunds and interact with other financial functions exposed through the API. Cybernews separately examined the broader leak and said the data included business emails, account information, product records, customer names and contact details and, in some instances, physical addresses. Researchers warned that linking customer identities with transaction and merchant information could facilitate highly targeted phishing and fraud. Full payment-card numbers were not reported as part of the 659-merchant dataset.

Leak Highlights Broader Developer Secret Exposure

How the specific 659 merchant credentials were originally obtained remains uncertain. Potential sources include infostealer malware, credentials accidentally committed to public code repositories, exposed environment files, continuous-integration logs and improperly secured backups or servers. Separate research published around the same time identified more than 50,000 unique Stripe-related API secrets exposed across public repositories, GitHub Actions logs and misconfigured web infrastructure, demonstrating that merchant-side credential leakage extends well beyond the 659 accounts represented in the released archive. Cybernews reported a somewhat different count from Hudson Rock’s analysis of the circulating material: 669 vendors and 1,033 compromised API keys. That differs from Ransomnews’ narrower count of 659 merchant accounts and underscores that researchers may be measuring different portions or versions of the dataset.

The threat actor also reportedly claimed to possess as many as 20,000 compromised Stripe APIs and suggested additional batches could be released, although that assertion has not been independently verified. For affected businesses, the immediate risk extends beyond previously exposed customer records. Any credential that remains active could potentially continue providing API access until it is revoked or rotated. The incident therefore represents a large-scale merchant credential compromise rather than evidence of a centralized Stripe breach. That distinction does little to reduce the potential consequences for the 688,363 customer records already exposed. It instead demonstrates how a payment platform’s legitimate APIs can become an extraction mechanism when businesses fail to adequately protect the secret credentials used to access them.

© 2026 Michaels Finance Corner. All rights reserved.