Leaked API Keys Expose Data From 659 Stripe Merchants
Stripe API keys allow online merchants to connect applications to the payments platform, retrieve transaction information and manage payment operations. If exposed, the credentials can give unauthorized users access to data and functions that should remain restricted. The incident points to compromised merchant credentials rather than a disclosed breach of Stripe’s core platform, underscoring the need for strict key storage, limited permissions and regular rotation.
API keys belonging to 659 online merchants across 42 countries were leaked, leading to about 35GB of customer and payment data being posted on a forum for free download. The dataset covers nearly 690,000 transactions. The report did not specify when the exposure occurred or disclose any financial losses. Security experts urged affected merchants to revoke and rotate their keys immediately, review payment configurations and examine access logs for suspicious activity.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →