1,033 Live Stripe Secret Keys Leaked via Exposed .env Files, 669 Vendors Affected
A threat actor published 1,033 active Stripe secret keys belonging to 669 vendors on an illicit forum on August 18, 2026, with claims of holding approximately 20,000 more for gradual release. The leaked keys carried charge capabilities and were accompanied by customer records including names, emails, addresses, and partial card details linked to real Stripe invoices. Security firm Hudson Rock, which analyzed the dump, found no evidence of infostealer malware on the affected vendor domains, pointing instead to automated mass-scanning of publicly accessible .env configuration files and debug logs. The breach affected businesses running entirely different technology stacks — from PHP storefronts to Node and Python services — ruling out any single vulnerable plugin or framework as the cause. Stripe itself was not compromised; the incident is attributed solely to deployment misconfigurations that inadvertently exposed sensitive credential files at scale.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in