Risk of spear phishing

Alleged Data Breach at Stripe: Merchant and Customer Data in the Darknet

Stripe
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Poetra.RH/Shutterstock.com

A 35 GB dataset containing Stripe customer data and active API keys has surfaced on the darknet. Maximum phishing danger for merchants.

A dataset of around 35 gigabytes containing sensitive information from merchants and customers of payment service provider Stripe has surfaced on a cybercrime forum. Initial analyses by security researchers at Cybernews and Hudson Rock suggest that the published material is authentic. The leaked dataset includes, among other things:

Ad
  • Merchant & transaction statistics: Customer numbers, revenue, and transaction volumes of individual online shops.
  • Customer data: Full names, email addresses, postal addresses, and linked purchase histories.
  • System access credentials: Discount codes, product logs, and compromised Stripe API keys.

Dangerous API keys and risk of spear phishing

Particularly explosive: According to cybersecurity firm Hudson Rock, the data contains at least 650 active secret keys. Through such API keys, attackers can potentially gain direct read and write access to merchant accounts in order to redirect payouts, make unauthorized charges, or initiate refunds.

In addition, linking real names with exact purchase histories enables highly targeted phishing campaigns (spear phishing), as criminals can trace precisely which products victims purchased in which online shops.

Not a direct Stripe hack, but a distributed data leak

Security experts emphasize that in all likelihood this is not a direct breach into Stripe’s core infrastructure. Instead, the API keys were presumably exposed negligently by the respective merchants themselves—for example, through accidental disclosures in source code repositories or log files.

Ad

The attacker claims to possess access to around 20,000 compromised Stripe APIs and threatens to release further data packages step by step. Affected companies are urgently advised to rotate and restrict their API keys immediately.

(Editorial Team)

Ad

Weitere Artikel