Stripe API Keys Exposed in Public GitHub Repositories, Threatening Payment Data
What Happened — Security researchers discovered multiple live Stripe secret keys embedded in publicly accessible GitHub repositories. The keys grant full access to the associated Stripe accounts, enabling attackers to create charges, retrieve payouts, and view sensitive payment information. Stripe has advised affected merchants to rotate the compromised keys immediately.
Why It Matters for Compliance & Audit Readiness
- Credential leakage is a classic SOC 2 CC6 (Logical Access) failure; continuous monitoring of secret management is required to prove controls are effective.
- Demonstrating timely key rotation and audit‑ready evidence of access‑control policies is a core component of a defensible SOC 2 audit.
- Verisq’s SOC 2 Access Controls capability automates secret‑management monitoring, providing real‑time alerts and evidence bundles for auditors.
Who Is Affected — Payment‑processing firms, SaaS platforms that embed Stripe, and any organization that stores API secrets in code repositories.
Recommended Actions
- Immediately revoke and rotate any exposed Stripe keys.
- Implement a secret‑scanning CI/CD gate to block credential commits.
- Map the incident to SOC 2 CC6 controls, collect evidence of key rotation, and log the remediation steps in your compliance repository.
Technical Notes — The exposed keys were found via automated GitHub searches that match the “sk_live_” prefix. No CVE is involved; the vector is insecure secret storage (misconfiguration). Affected data includes transaction IDs, customer emails, and payout details. Source: The Hacker News