mimile
Back to feed

Cybernews reports alleged Stripe customer data leak on cybercrime forum

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Cybernews reports alleged Stripe customer data leak on cybercrime forum

Cybernews reports that a threat actor on a cybercrime forum claimed to offer a 35GB dataset allegedly containing Stripe customer and transaction logs. Hudson Rock said the dataset included 669 vendors and 1,033 compromised API keys. The actor claimed the released data was only a small part of a package of about 20,000 compromised Stripe APIs.

Key Facts

  • A 35GB dataset allegedly linked to Stripe customers surfaced on a cybercrime forum.
  • Hudson Rock reported the dataset contained 669 vendors and 1,033 compromised API keys.
  • The threat actor claimed to possess about 20,000 compromised Stripe APIs and said the released data was a small part of the package.
  • The dataset includes business account information such as emails, Stripe API keys, and account flags, alongside customer logs with names and contact information.

The Alleged Dataset

Cybernews reported that a listing on a cybercrime forum claimed to offer about 35GB of data described as logs from companies using Stripe for payment management. The alleged dataset includes shop statistics such as customer numbers, transaction counts, and processed amounts. It also contains business account information, including emails, Stripe API keys, and account flags. Customer logs include full names, contact information, and in some cases addresses, alongside coupon codes and product logs.

Hudson Rock Findings

Cybersecurity firm Hudson Rock reported that the dataset contained 669 specific vendors and 1,033 compromised API keys. Hudson Rock researchers said they spoke to the threat actors minutes after the data was released. The actor claimed the released data represented only a small part of the package and said they possess approximately 20,000 compromised Stripe APIs. The actor said they intended to release the remaining data in subsequent batches.

Fraud Risk Assessment

Cybernews researchers said the threat actor has been active for a long time and that the information examined so far appears legitimate. The dataset size is broadly consistent with the claimed 35GB. The exposed records include transaction logs with user IDs that can be linked to names and contact information. The user ID linkage makes the dataset considerably more valuable to criminals than a simple collection of names and email addresses.

2 sources

Cybernews reports alleged Stripe customer data leak on cybercrime forum