Mark RadarMARK RADAR
About
EN
Sign in

Leaked API Keys Expose Data From 659 Stripe Merchants

1 reports · First detected 2026-08-24 · Last active 2026-08-24

Stripe API keys allow online merchants to connect applications to the payments platform, retrieve transaction information and manage payment operations. If exposed, the credentials can give unauthorized users access to data and functions that should remain restricted. The incident points to compromised merchant credentials rather than a disclosed breach of Stripe’s core platform, underscoring the need for strict key storage, limited permissions and regular rotation.

API keys belonging to 659 online merchants across 42 countries were leaked, leading to about 35GB of customer and payment data being posted on a forum for free download. The dataset covers nearly 690,000 transactions. The report did not specify when the exposure occurred or disclose any financial losses. Security experts urged affected merchants to revoke and rotate their keys immediately, review payment configurations and examine access logs for suspicious activity.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)