Hundreds of leaked Stripe merchant keys have exposed payment and payout capabilities, creating a significant risk for online businesses and their customers. The incident, which surfaced in August 2024, involved the posting of active Stripe merchant secret keys on an underground data-trading forum, compromising sensitive data and payment operations for hundreds of merchants.
The Stripe Merchant Key Leak: What Happened
On 18 August 2024, a large archive containing Stripe merchant API keys and related customer data appeared for free download on a popular data-trading forum. This leak involved active credentials from 659 separate merchant accounts, with a dataset totalling roughly 35 GB and affecting about 688,000 individuals. The exposed credentials included 650 live secret keys and nine restricted keys, enabling full or partial access to merchant Stripe accounts.
Contrary to initial forum claims, Stripe itself was not breached. Detailed examination by RansomNews, who reported the incident and alerted Stripe before publication, confirmed that the breach resulted from the compromise of merchant credentials, not Stripe’s infrastructure. Attackers appear to have obtained these secret keys through various sources, such as infostealer malware, exposed code repositories, public environment files, or poorly secured backups. With these credentials, the attacker used legitimate Stripe API calls to access payment and customer records from each affected account.
The data was made publicly available, rather than being sold privately, which increases the risk of further misuse by a wider range of threat actors. The exposed archive reportedly contained up to 27 different resource types per merchant, such as customer records, payment data, and payout information.
Technical Details: Scale, Impact and Attack Method
The merchant keys in this leak were highly sensitive: Stripe secret keys grant programmatic access to a business’s payment infrastructure, including the ability to view transactions, initiate charges, and process payouts. In most cases, these keys are the backbone of e-commerce operations, meaning exposure can be devastating.
Key Technical Facts
- Date of exposure: 18 August 2024
- Data posted: Free download on a data-trading forum
- Size of dataset: 35 GB
- Merchants affected: 659 accounts
- Individuals affected: Estimated 688,000
- Key types: 650 live secret keys, 9 restricted keys
- Resource types per merchant: Up to 27 (including customer and payment data)
The attacker likely aggregated the credentials from a mix of sources before testing them to verify which were still active. Using these keys, they performed standard API requests to collect all accessible data from each merchant account. As Stripe secret keys are not bound to a single IP or environment, any party in possession of an active key can perform sensitive operations unless additional security measures are enforced by the merchant.
Although the forum post claimed Stripe itself was compromised, RansomNews’ analysis confirmed that only merchant credentials were involved. This distinction is critical: the incident highlights the wide-ranging consequences of poor credential management among individual businesses, as opposed to a platform-wide vulnerability.
Timeline and Current Status of Exploitation
The timeline of the incident is as follows:
- Prior to 18 August 2024: Attackers aggregate Stripe merchant credentials from infostealer logs, exposed code, and misconfigured storage.
- 18 August 2024: Credentials and associated data posted as a free archive on an underground forum. The post falsely claims a breach of Stripe itself.
- Shortly after posting: RansomNews verifies the material offline and alerts Stripe to the exposure before publishing their findings. They avoid directly accessing payment or customer records.
- After disclosure: Stripe works to identify affected merchants, rotate compromised keys, and mitigate further access with the help of responsible disclosure.
At present, most of the secret keys in the leak have been revoked or rotated by Stripe and the impacted merchants. However, because the dataset was distributed freely, there remains an ongoing risk that threat actors may attempt to exploit any keys that were not promptly disabled.
Risks and Potential Consequences for Merchants
This leak exposes several major risks to the affected merchants and their customers:
- Account takeover: Attackers with a live secret key can access all data, transactions and payment history for a merchant’s Stripe account.
- Fraudulent charges and payouts: Malicious parties can initiate payments or divert funds, potentially stealing revenue or laundering money.
- Customer data exposure: Personal and financial details of customers, including payment methods, could be accessed or exploited for further fraud.
- Regulatory and reputational impact: Merchants may face regulatory scrutiny and reputational harm due to loss of customer trust and compliance obligations.
For the 688,000 individuals whose data was exposed, this incident creates a risk of targeted phishing, financial fraud, or identity theft if their personal information is abused.
Why This Matters and Immediate Actions
This event underscores the critical nature of API key management for any business using third-party payment platforms like Stripe. Exposure of a single secret key can enable full account compromise, making proactive credential security essential.
Organisations should:
- Rotate all secret keys suspected of exposure immediately.
- Audit application and code repositories for hardcoded or publicly accessible credentials.
- Implement restricted keys wherever possible to limit the blast radius of future leaks.
- Monitor for suspicious API activity and configure alerts for unauthorised operations.
Merchants affected by this leak should work with Stripe to ensure all compromised keys are revoked and customer notification obligations are met where necessary.
Originally reported by cybersecuritynews.com.







