API keys from 659 Stripe merchant accounts leaked on a data forum, exposing 688,000 customer records and payment data.
Regulation & Gov ·
API keys from 659 Stripe merchant accounts were published on a data-trading forum on August 18, according to Ransomnews. The disclosure included roughly 35GB of customer and payment data spanning approximately 688,000 customer records. Among the exposed credentials were 650 live secret keys and nine restricted keys; metadata indicated that 519 of the compromised accounts held both payment-receiving and payout capabilities.
The breach did not originate from Stripe itself. Instead, the merchant-side API keys were likely obtained through several attack vectors: infostealer malware, credentials published in public code repositories, exposed environment files, or misconfigured backups. Each of these pathways represents a common supply-chain weakness affecting merchants rather than the payment platform's infrastructure directly.
The incident exposes a critical dependency in the Stripe ecosystem—merchants' handling of credentials and secrets. It remains unclear how many of the 688,000 customer records contained sensitive payment information, whether any of the exposed keys have been actively misused, or what remediation steps Stripe has communicated to affected merchants.