The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

API keys of 659 Stripe merchants leaked with 688,000 customer records

Make The Latest Crypto News preferred on Google
A glowing key icon over a striped payment terminal, with a lock and cascading data rows.
A glowing key icon over a striped payment terminal, with a lock and cascading data rows.

An unknown attacker has published API keys belonging to 659 Stripe merchants on a trading forum for stolen data. Alongside the keys, nearly 688,000 customer records and around 35 GB of payment information have appeared. The data has been made available for free, not sold. Stripe itself has not been compromised. The keys originate from individual merchants, not from Stripe’s own systems.

In brief:

  • 650 active secret API keys and 9 restricted keys belonging to Stripe merchants have been leaked.
  • The dataset contains 688,363 customer records and payment information from 42 countries.
  • Stripe itself has not been hacked; the keys are thought to have reached the attacker via infostealers or public repositories.

What exactly was leaked

The dataset was published on 18 August 2026 by a user named Satanic, a well-known account on the forum in question with nearly 2,000 reputation points. According to Ransomnews, which analysed the files offline, the dump contains 17,654 files divided into folders per merchant. Each folder contains up to 27 different types of Stripe objects, including customer profiles, payments, invoices, payouts and disputes.

Of the 659 leaked keys, 650 are so-called secret keys, while the remaining 9 are restricted keys. The attacker validated all the keys: they all worked at the time of collection. According to the metadata in the dump, 573 accounts could receive payments, 531 could make payouts, and 519 had both capabilities.

No card numbers, but access was complete

Full card numbers were not found in the dataset. Stripe does not process them through its API, so they would not be visible even in a genuine key leak. The customer records do contain the last four digits of payment cards, the brand, the expiry date and the country of issue.

A secret Stripe API key provides full programmatic access to an account. Anyone who obtains such a key can read customer data, create payments, issue refunds and even change the bank details for payouts. Whether the keys are still active depends on whether the affected merchants have already replaced them. There is no evidence of that in the data.

Ransomnews says it checked the structure of the files, not their content. The object identifiers, session prefixes and field sets in the dataset match genuine Stripe API output. The publisher notified Stripe prior to publication.

How the keys were obtained

The dataset does not reveal how the keys were gathered. Ransomnews points to the most common causes: keys stored in infostealer logs from developer machines, keys accidentally committed to public code repositories, or keys in poorly secured environment files and backups.

The merchants come from 42 countries. Most affected accounts are based in the United States (212), followed by the United Kingdom (81), France (57), Canada (38), Brazil (30) and Australia (27).

Ransomnews advises all Stripe users to replace their secret API keys, review their payment settings and search their own repositories and environment files for exposed keys. Merchants that fail to do so risk an attacker redirecting payouts to their own bank account.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Scam News

More news ›