Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys
A forum user posting as Satanic has published what they describe as 662 datasets totalling 33GB, exported from Stripe merchant accounts using 1,033 compromised API keys. Despite the thread title, the post does not describe a compromise of Stripe itself: the keys are merchant secrets, and the data was pulled through Stripe's own interface using them. The seller claims a validation pass confirming which keys remain live, including whether each account can still take payments and issue payouts. The exported material is said to contain 1,350,336 unique customer email addresses from more than six million matches, and a table of 688,000 customers with names, phones, registration dates and IP addresses. The claim is unverified.
▣Post details
!Allegedly included
- Validated merchant API keys
- Merchant account identifiers
- Business names and domains
- Merchant contact emails
- Payment and payout status
- Customer names and emails
- Customer phone numbers
- Registration dates
- Customer IP addresses
- Charge and refund records
- Invoice and subscription data
- Payout and transfer logs
- Dispute records
- Checkout session data
◱Screenshots
⚠Potential impact
The keys matter more than the data. A merchant secret key is not a record of past activity but a live instrument, and the seller claims to have checked which accounts still accept charges and issue payouts. Any key that has not been rotated would let a holder read the account continuously, issue refunds, and alter payout arrangements, so the exposure grows for as long as it goes unnoticed. For consumers, the exported tables reportedly pair name, email, phone and IP with purchase and subscription history at a named business, which supports unusually convincing fraud, since an attacker can reference a real order at the correct merchant. Card numbers are not exposed this way, but disputes, refunds and subscription records are exactly the material a payment support impersonation needs. The affected merchants are scattered across jurisdictions and many are likely small operators without the means to detect misuse of their own keys.
iStatus
UnverifiedThe framing in the thread title is misleading and likely to be repeated inaccurately. Nothing in the post indicates a compromise of Stripe's own systems: the described method is theft of merchant credentials, most often from exposed configuration, repositories or infected developer machines, followed by ordinary use of the payment interface. The export structure shown matches standard resources any account holder can retrieve with a valid key, which is consistent with that account and inconsistent with a platform breach. Dark Web Informer is not reproducing the download route, key fragments, account identifiers, merchant emails or business names from the samples. The claim is unverified, and affected merchants, not Stripe, would be the parties needing to respond.
DARK WEB INFORMER - THREAT INTELLIGENCE