
Hundreds of Stripe merchant accounts may have had payment and payout access exposed after API credentials appeared in a roughly 35GB dataset posted to a data-trading forum, Ransomnews reported.
Metadata accompanying the dataset suggested 573 accounts had credentials that could accept payments and 531 could make payouts, while 519 had both capabilities. Ransomnews did not independently test whether the credentials worked.
The files contained credentials linked to 659 Stripe merchant accounts, comprising 650 live secret keys and nine restricted keys, according to the report. The dataset also contained customer and payment information tied to 688,363 customer records.
Ransomnews said the exposure did not result from a compromise of Stripe’s systems. Full payment card numbers were also absent from the leaked data.
Source: Ransomnews