← Back to feed
Breaches & RansomwareEmerging1 sourceAug 19, 2026 · 08:33via Security Affairs

50,000 Stripe Secrets Leaked in Public Code

Brief

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours.

Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total.

The research is practical rather than theoretical: the team tested a sample of the keys, found a meaningful portion still active, and documented exactly how quickly a fraudster could exploit them. The answer is fast.

“A dataset published on a data-trading forum on 18 August 2026 contains live Stripe API keys for 659 merchant accounts, along with roughly 35 GB of customer and payment data pulled from them.” reads the report published by Ransomnews.

Read more on Security Affairs