19/08/2026
🚨 Threat Actor Claims Major Payment Platform Breach — Customer Data & API Keys Allegedly Compromised
DarkFeed has identified a newly published post on an underground cybercrime forum claiming a significant breach involving one of the world's largest online payment infrastructure providers.
According to the threat actor's post, the alleged compromise occurred on August 17, 2026, with the actor describing the release as “Part 1” — potentially indicating that additional data may follow.
The actor claims to possess:
🔹 662 compromised databases
🔹 1,033 API keys
🔹 Approximately 33 GB of data
🔹 688,000 unique customer records
The advertised customer dataset allegedly contains fields including email addresses, full names, first/last names, phone numbers, registration dates, and IP addresses.
The presence of allegedly compromised API keys makes this claim particularly noteworthy, as exposed credentials could potentially create risks beyond the disclosure of customer information depending on their validity, permissions, and associated systems.
At this stage, these claims originate from an underground forum post and should be treated as unverified until independently confirmed.
DarkFeed continues to monitor underground forums, ransomware infrastructure, leak sites, and cybercriminal communities for emerging threats before they become widely reported.
🔎 Want visibility into what threat actors are discussing and selling underground? Track emerging threats with DarkFeed:
darkfeed.io