A hacker posted on August 18 on PwnForums the API keys of 659 merchants using Stripe, exposing approximately 688,363 customer records across 42 countries, with a data volume estimated between 33 and 35 gigabytes. The leak did not originate from Stripe’s infrastructure, but from the merchants themselves, who left their secret keys accessible in public code repositories, misconfigured servers, and machines infected with infostealer malware. In total, over 50,000 Stripe API keys were found exposed in public domains, with the majority being live-mode secret keys. Merchants operating in the European Union face potential enforcement under GDPR, with fines reaching up to 4% of annual global revenue.
Source: Read the original article

