uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark
Advertisement

API Keys From 659 Stripe Merchants Reportedly Leaked Alongside 688,000 Customer Records

A reported dataset exposed 659 Stripe merchant API keys and 688,363 customer records, while Stripe systems were reportedly not compromised.

API keys associated with 659 Stripe merchant accounts were reportedly exposed alongside roughly 35GB of customer and payment data containing 688,363 customer records, according to Ransomnews. The dataset was published on a data-trading forum and reportedly contained 650 live secret keys and nine restricted keys.

The report, shared by @WuBlockchain on X, said the exposed information included merchant credentials and customer-related payment data. However, Ransomnews did not test the keys itself, meaning the reported capabilities of the credentials were based on metadata contained in the dataset rather than independent verification.

The report also stated that Stripe’s own systems were not compromised and that the dataset did not contain full payment card numbers.

Dataset Contains 659 Stripe Merchant Accounts

The reported dataset contained API keys connected to 659 Stripe merchant accounts, according to Ransomnews.

API keys are credentials used by applications and services to interact with payment infrastructure. Depending on their permissions, such credentials can allow software to perform specific actions on behalf of a merchant account.

The dataset reportedly included 650 live secret keys and nine restricted keys. The distinction is significant because secret keys can provide broader access to Stripe account functionality, while restricted keys are designed to limit access to cryptocurrency particular operations or resources.

Ransomnews said it identified the credentials within a dataset that had been published on a data-trading forum. The report did not establish that every key remained usable at the time of publication because the outlet did not test the credentials itself.

Instead, the reported status and capabilities were derived from collector metadata associated with the dataset.

Nearly 688,000 Customer Records Included

Alongside the merchant API keys, the dataset reportedly contained approximately 35GB of customer and payment information.

The information covered 688,363 customer records, making the reported exposure significantly broader than the merchant credentials alone.

The combination of merchant-level credentials and customer data raises questions about the nature of the information contained in the dataset. However, the available report does not provide a complete breakdown of the individual data fields included in the records.

Ransomnews also said the dataset did not markets contain full card numbers. That limits the type of payment information reportedly exposed, although the report still described a substantial amount of customer and payment-related data.

The absence of full card numbers does not necessarily mean that the dataset contained no sensitive information. Customer records and merchant credentials can contain other forms of information that require appropriate security controls.

Metadata Shows Different Merchant Capabilities

Collector metadata associated with the dataset reportedly provided information about the capabilities linked to the exposed accounts.

According to the report, 573 accounts could accept payments, while 531 could make payouts. A total of 519 accounts were indicated as having both capabilities.

These figures provide an indication of the types of Stripe functionality associated with the exposed accounts. However, Ransomnews emphasized that it did not independently test the keys.

As a result, the reported capabilities finance should be understood as information derived from the dataset’s metadata rather than confirmed access obtained by the reporting outlet.

The distinction is important when evaluating the potential impact of an exposed credential dataset. A key appearing in a collection does not by itself establish that it remains active, valid or usable.

Stripe Systems Reportedly Not Compromised

Ransomnews reported that Stripe’s own systems were not compromised in the incident described by the dataset.

Instead, the reported exposure involved information associated with individual merchant accounts that appeared in a dataset published on a data-trading forum.

The distinction separates an alleged compromise of individual merchant credentials or data from a breach of Stripe’s central infrastructure. Based on the information provided, the report did not claim that attackers penetrated Stripe’s core systems.

The report also stated that no full card numbers were present in the dataset, although it did contain customer and payment-related information.

The findings highlight the importance of protecting API credentials used to connect third-party applications with payment platforms. Merchant accounts can rely on API keys for automated payment processing and other account functions, making credential security an important part of broader payment infrastructure security.

According to Ransomnews, the dataset contained API keys tied to 659 Stripe merchants and roughly 35GB of information covering 688,363 customer records. The report said Stripe itself was not compromised, while noting that the exposed keys markets were not independently tested.


Writer: Victoria Hale  
Technology & Blockchain Writer

Victoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.

She prioritises clarity and accuracy when explaining technical developments to a general audience.

Check out other news and articles on Google News

Disclaimer:

The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.

HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember:  crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.

Stay curious, stay safe, and enjoy the ride! hoka.news

Advertisement