Skip to content
Blog Post

Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs

InfoStealers
6 min read
Stripe Data Breach: Analysis of Satanic’s Release

Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs

On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform.

Initial forum post by Satanic detailing the 33GB Stripe breach
Figure 1: The initial forum post by Satanic announcing the breach, detailing the compromise of databases and 1,033 API keys, totaling 33GB, along with millions of email matches.

Satanic is a known entity within the cybercrime ecosystem, previously verified by Hudson Rock researchers for their involvement in large-scale breaches. We previously documented their activities in the Hot Topic breach.

Pwnforums post listing by Satanic
Figure 2: The pwnforums activity of ‘Satanic’, showing a history of high-profile database leaks, including the recent Hot Topic breach and the newly announced Stripe compromise.

The Initial Release: A Glimpse into the Compromise

The initial dump released on August 18th contained detailed information pertaining to 669 specific vendors, alongside 1,033 compromised API keys. The volume of the data is reported as 33GB.

Hudson Rock researchers spoke to the threat actors minutes after the release of the data. During this exchange, they claimed that the released data represents only a fraction of their total haul. According to the actor, they possess approximately 20,000 compromised Stripe APIs, which they intend to release in subsequent batches.

Telegram message from Satanic claiming 20k APIs
Figure 3: Direct communication between Hudson Rock researchers and the threat actor, where they claim possession of roughly 20,000 Stripe API keys, threatening staggered releases.

Further corroborating their claim of a staggered release, while the forum post advertises a 33GB database, the archive provided in the actual download link is only 2.37GB. This significantly smaller file size supports the threat actor’s assertion that this initial drop is merely a taste of a much larger, ongoing compromise.

Download link showing a 2.37GB file size
Figure 4: The download link provided by the threat actor reveals a file size of 2.37GB, corroborating their claim that the released data is just a small portion of the 33GB total they allegedly possess.

Analysis of the Leaked Data

Our preliminary analysis of the released files reveals a high level of access to vendor operations. The compromised data affects the core of the affected businesses’ financial and operational integrity.

1. Scope of Affected Domains

The variety of businesses affected is vast, ranging from small consultancies to large e-commerce operations across multiple currencies and jurisdictions. The root directory of the leak shows the compromised domains.

List of folders showing various compromised domains and their customer counts
Figure 5: A snapshot of the root directory showing various compromised domains, highlighting the diverse range of victims across different countries and currencies, with some vendors holding thousands of customer records.

2. Extensive Customer and Transaction Records

Navigating into the specific vendor folders reveals a highly organized structure, containing detailed records of customers, balances, charges, and payouts.

Directory structure showing various Stripe data categories
Figure 6: A view into the directory structure of the leaked data for a specific vendor, revealing comprehensive folders for accounts, balances, charges, customers, invoices, and more.
JSON summary of a compromised account showing thousands of customers and millions in volume
Figure 7: A JSON snippet exposing the scale of a single compromised vendor account, detailing over 22,000 customers and more than $5 million in paid invoices.

3. Sensitive Customer Information and Invoicing

The breach exposes granular details of individual transactions, including customer names, email addresses, phone numbers, and the specific services they were billed for. The data corresponds to real Stripe invoices, adding immense validity to the claims. For example, some of the leaked CSV files contained the personal details, email addresses, home addresses, IP addresses and purchase history for users.

Beyond standard PII, our analysis of the raw invoice datasets reveals extensive technical metadata. The leaked records contain the purchaser’s exact IP address at the time of transaction, internal transaction IDs, and identifiers for third-party platform integrations. This metadata provides attackers with a comprehensive digital footprint of the vendor’s customer base and internal tech stack.

Spreadsheet detailing customer emails, names, phones, and invoice URLs
Figure 8: A spreadsheet extracted from the leak, clearly displaying customer PII (emails, names, phone numbers) alongside descriptions of services rendered and direct links to hosted Stripe invoices.

Furthermore, accessing these rendered invoices exposes additional financial metadata, including the last four digits of the customer’s credit card, further compromising the users’ financial privacy.

Example of a rendered Stripe invoice
Figure 9: An example of a legitimate-looking Stripe invoice accessed via the leaked URLs, confirming the validity of the exposed data and revealing partial payment details.

4. Operational Compromise: API Keys and Business Logic

A critical component of this leak is the exposure of live API keys and internal operational data like promotional codes.

The exposure of live API keys presents a severe risk. With these keys, threat actors can programmatically access the vendor’s Stripe account. Depending on the permissions associated with the key, this could allow attackers to view sensitive customer data, initiate unauthorized refunds, alter account settings, or potentially reroute payments, leading to direct financial loss and severe reputational damage. In the leaked data, some of the exposed keys belong to accounts explicitly configured with charge capabilities enabled, and are labeled as standard type API keys, indicating broad access to initiate financial transactions.

JSON snippet showing an exposed sk_live API key with charge capabilities
Figure 10: A snippet from the leaked data exposing a vendor’s live API key (“sk_live_…”), confirming that the account has charge capabilities enabled, which grants severe financial control to the attacker.

The exposure of active promotional codes also introduces a direct avenue for financial exploitation. Vendors frequently generate high-value discount codes intended for narrow, restricted use (e.g., customer retention, employee perks, or VIP access). Often, vendors create codes with very large percentages off for specific purposes not meant to be used by a lot of people. With these codes now public in the database, malicious actors could mass-apply them, leading to severe inventory and revenue drain before the vendor even realizes the codes have been heavily abused.

Spreadsheet showing exposed Stripe promotional codes and discounts
Figure 11: A leaked spreadsheet detailing internal promotional codes, their discount amounts, and durations. If abused, these codes can cause massive revenue loss for the affected vendors.

Investigating the Attack Vector

While Satanic is a known entity verified by Hudson Rock researchers for their involvement in large-scale breaches utilizing infostealer credentials, our telemetry reveals an interesting anomaly regarding this specific leak. Initial investigations show no infostealer infections associated with the specific vendor domains observed in the data.

Furthermore, analysis of the raw metadata across multiple leaked accounts shows that the affected vendors utilize completely different tech stacks, plugins, and business models. This indicates that the threat actor is not targeting a single vulnerable WordPress plugin or specific software suite.

Instead, this lack of localized infostealer activity, combined with the sheer volume of 20,000 allegedly compromised API keys across varied platforms, points toward a broader systemic attack vector. It is highly likely the threat actors are running automated bots to mass-scan websites for misconfigured, publicly exposed environment variables (.env files) or debug logs that leak plaintext “sk_live_” keys. Alternatively, this could indicate a compromise of a shared piece of infrastructure, such as a cloud hosting provider or deployment tool used by these vendors.

Hudson Rock is actively monitoring this situation. If Satanic’s claims regarding the 20,000 API keys are accurate, this event represents a major compromise of payment infrastructure data. We advise organizations utilizing Stripe to immediately review their API key security, audit their environment variables, and monitor for anomalous activity.

To learn more about how Hudson Rock protects companies from imminent intrusions caused by info-stealer infections of employees, partners, and users, as well as how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:

https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:

www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!

Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock

Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Continue reading

Related articles

Free Tools Check your exposure