Stripe merchant API key leak exposes more than 50,000 unique keys

More than 50,000 unique Stripe merchant API keys have been exposed through public code repositories, GitHub Actions logs, infostealer malware and misconfigured web servers, according to reporting by Security Affairs and Ransomnews. A dataset posted on PwnForums on August 18, 2026, by a hacker using the name Satanic reportedly contained live credentials for 659 merchant accounts and about 688,363 customer records spanning 42 countries. The data was estimated at between 33 and 35 gigabytes. Stripe itself was not breached; the credentials were harvested from merchants and other exposed environments. Tests found a substantial share of the keys remained active, allowing access to customer lists and stored payment methods, creation of charges and payment links, refunds to attacker-controlled accounts, Webhook changes and, where enabled, connected Stripe accounts. The hacker also claimed to hold about 20,000 additional keys, suggesting the published dataset may not represent the full exposure.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.