news.mlab.sh
Back to the feed
threat-intel

Stripe visé par une fuite revendiquée de 662 bases de données !

High
Summary

A purported data leak claiming to contain 33GB of Stripe data, including 1.033 API keys and 662 customer databases, has been published by a known data broker. The leak includes 6.16 million email addresses, 688,000 complete customer profiles (with contact details and IP addresses), and a detailed dataset covering various Stripe operations. The lack of technical details regarding the breach makes it difficult to determine the source of the data, but the combination of sensitive information suggests a significant risk for criminal intelligence operations.

A purported data leak, published on August 18, 2026, claims to expose 33GB of data from Stripe, including 1,033 compromised API keys and 662 customer databases. The publication, originating from a well-known data broker, details a substantial collection of sensitive information. It includes 6.16 million email addresses, with 1.35 million unique addresses, and 688,000 complete customer profiles, each containing details such as address, phone number, IP address, and date of registration.

The leak presents a structured dataset, organized in CSV and JSON files, covering a wide range of Stripe operations, including application fees, balances, transactions, payments, sessions, customers, disputes, events, invoices, payment intentions, transfers, and tax rates. The data is presented in an organized format, suggesting it may be derived from exports of multiple Stripe accounts.

Notably, the presence of API keys and customer data significantly elevates the value of this leak for criminal intelligence activities. The combination of identity information, email addresses, phone numbers, merchant accounts, and payment activity can be used to map organizations, target individuals, and craft targeted phishing campaigns.

Despite the substantial volume of data, the publication lacks technical details regarding the alleged breach. There is no information on the initial attack vector, compromised servers, vulnerabilities exploited, stolen credentials, or data exfiltration methods. This absence hinders efforts to definitively attribute the leak to a direct breach of Stripe’s infrastructure. Stripe has been contacted for comment and is awaiting a response.

Read the full article at ZATAZ