Skip to content

Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys

Breach Report Multiple Countries E-commerce / Payment Credentials Free Download

Merchant Data From Hundreds of Stripe Accounts Allegedly Exported Using 1,033 Compromised API Keys

A forum user posting as Satanic has published what they describe as 662 datasets totalling 33GB, exported from Stripe merchant accounts using 1,033 compromised API keys. Despite the thread title, the post does not describe a compromise of Stripe itself: the keys are merchant secrets, and the data was pulled through Stripe's own interface using them. The seller claims a validation pass confirming which keys remain live, including whether each account can still take payments and issue payouts. The exported material is said to contain 1,350,336 unique customer email addresses from more than six million matches, and a table of 688,000 customers with names, phones, registration dates and IP addresses. The claim is unverified.

API keys1,033
Unique emails1.35M
Datasets662
ActorSatanic

Post details

TargetStripe merchant accounts
CountryMultiple, US, FR, LU seen
SectorOnline payments, mixed retail
ListingFree, reply to unlock
Volume33GB, 662 datasets
Root causeClaimed merchant key theft
Observed
ActorSatanic

!Allegedly included

  • Validated merchant API keys
  • Merchant account identifiers
  • Business names and domains
  • Merchant contact emails
  • Payment and payout status
  • Customer names and emails
  • Customer phone numbers
  • Registration dates
  • Customer IP addresses
  • Charge and refund records
  • Invoice and subscription data
  • Payout and transfer logs
  • Dispute records
  • Checkout session data

Screenshots

Potential impact

The keys matter more than the data. A merchant secret key is not a record of past activity but a live instrument, and the seller claims to have checked which accounts still accept charges and issue payouts. Any key that has not been rotated would let a holder read the account continuously, issue refunds, and alter payout arrangements, so the exposure grows for as long as it goes unnoticed. For consumers, the exported tables reportedly pair name, email, phone and IP with purchase and subscription history at a named business, which supports unusually convincing fraud, since an attacker can reference a real order at the correct merchant. Card numbers are not exposed this way, but disputes, refunds and subscription records are exactly the material a payment support impersonation needs. The affected merchants are scattered across jurisdictions and many are likely small operators without the means to detect misuse of their own keys.

iStatus

Unverified

The framing in the thread title is misleading and likely to be repeated inaccurately. Nothing in the post indicates a compromise of Stripe's own systems: the described method is theft of merchant credentials, most often from exposed configuration, repositories or infected developer machines, followed by ordinary use of the payment interface. The export structure shown matches standard resources any account holder can retrieve with a valid key, which is consistent with that account and inconsistent with a platform breach. Dark Web Informer is not reproducing the download route, key fragments, account identifiers, merchant emails or business names from the samples. The claim is unverified, and affected merchants, not Stripe, would be the parties needing to respond.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest