logo

50,000 Stripe Secrets Leaked in Public Code

ID: 044fb8cb-d2aa-53c1-b059-08d84c6f73ee

STIX ID: report--044fb8cb-d2aa-53c1-b059-08d84c6f73ee

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

Ransomnews researchers found over 50,000 exposed Stripe API keys in public repositories, GitHub Actions logs, and misconfigured servers; a dataset published on a forum contained live keys for 659 merchant accounts and roughly 35 GB of customer/payment data. The team validated many keys as active and showed attackers could rapidly access customer lists, create fraudulent payment links, charge cards, issue refunds, and modify webhooks, and the report recommends auditing and rotating keys, using restricted keys, enabling secret scanning and Stripe Radar rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.