Threat Actor "Satanic" Leaks 33GB of Stripe Merchant Data on Cybercrime Forum
On 18 August 2026, the threat actor known as "Satanic" uploaded over 33GB of allegedly stolen Stripe-related files to the cybercrime forum PwnForums. The actor, previously linked to breaches involving ClickFunnels, WooCommerce, and Magento, claimed possession of 20,000 compromised Stripe API keys, though only 1,033 exposed keys many with the sk_live_ prefix for live payment environments were verified in the leaked dataset.
Analysis by Hackread.com revealed 669 merchant account folders and 323 unique business domains after filtering duplicates and generic email providers. The breach did not stem from a compromise of Stripe’s systems but rather from exposed merchant credentials. Potential sources include hardcoded API keys in public GitHub repositories, unsecured configuration files, infostealer malware, or automated scans for exposed .env files.
The leaked data contained 688,363 customer records, including:
- Personal details (names, emails, phone numbers, addresses)
- Partial payment card data (last four digits, brand, expiry dates)
- Transaction histories (billing amounts, invoices, IP addresses)
- Active discount codes and internal identifiers
For 519 merchant accounts with both payment and payout capabilities, the exposure could enable fraudulent charges, unauthorized refunds, or payout redirection if the keys remain active. While the dataset does not confirm whether all keys are still valid, the financial and privacy risks for affected merchants and customers are significant.
Stripe has not commented on the incident, but the breach underscores the dangers of unsecured API keys and poor credential hygiene in payment processing environments.
Source: https://hackread.com/hacker-leak-stripe-merchant-api-keys-customer-records/
Adobe Commerce cybersecurity rating report: https://www.rankiteo.com/company/adobe-commerce
Stripe cybersecurity rating report: https://www.rankiteo.com/company/stripe
ClickFunnels cybersecurity rating report: https://www.rankiteo.com/company/clickfunnels
WooCommerce cybersecurity rating report: https://www.rankiteo.com/company/woocommerce
"id": "ADOSTRCLIWOO1787611224",
"linkid": "adobe-commerce, stripe, clickfunnels, woocommerce",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '688,363',
'industry': 'Payment Processing',
'name': 'Stripe Merchants',
'type': 'Business'}],
'attack_vector': ['Exposed API keys',
'Hardcoded credentials in public repositories',
'Infostealer malware',
'Automated scans for exposed .env files'],
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '688,363',
'personally_identifiable_information': ['Names',
'Emails',
'Phone numbers',
'Addresses',
'IP addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal details',
'Partial payment card data',
'Transaction histories',
'Active discount codes',
'Internal identifiers']},
'date_detected': '2026-08-18',
'date_publicly_disclosed': '2026-08-18',
'description': "On 18 August 2026, the threat actor known as 'Satanic' "
'uploaded over 33GB of allegedly stolen Stripe-related files '
'to the cybercrime forum PwnForums. The actor claimed '
'possession of 20,000 compromised Stripe API keys, though only '
'1,033 exposed keys were verified in the leaked dataset. The '
'breach did not stem from a compromise of Stripe’s systems but '
'rather from exposed merchant credentials, including hardcoded '
'API keys in public GitHub repositories, unsecured '
'configuration files, infostealer malware, or automated scans '
'for exposed .env files. The leaked data contained 688,363 '
'customer records, including personal details, partial payment '
'card data, transaction histories, and active discount codes.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': '688,363 customer records',
'identity_theft_risk': 'High',
'operational_impact': 'Potential fraudulent charges, unauthorized '
'refunds, or payout redirection',
'payment_information_risk': 'High',
'systems_affected': 'Stripe merchant accounts'},
'lessons_learned': 'The breach underscores the dangers of unsecured API keys '
'and poor credential hygiene in payment processing '
'environments.',
'post_incident_analysis': {'root_causes': 'Exposed merchant credentials, '
'including hardcoded API keys in '
'public repositories and unsecured '
'configuration files'},
'references': [{'source': 'Hackread.com'}, {'source': 'PwnForums'}],
'threat_actor': 'Satanic',
'title': "Threat Actor 'Satanic' Leaks 33GB of Stripe Merchant Data on "
'Cybercrime Forum',
'type': 'Data Breach',
'vulnerability_exploited': 'Unsecured API keys and poor credential hygiene'}