📣 Send us your press release
Site updates every 15 minutes
Technology

Dark web listing contradicts Dodo Payments' data breach disclosures

Bengaluru-based payments company Dodo Payments stated on August 17 that a breach of an internal analytics system did not compromise API keys, passwords, or credentials. However, a dark web listing reviewed by MediaNama claims the stolen dataset includes such sensitive information.

1 September 2026
Dark web listing contradicts Dodo Payments' data breach disclosures
Image is an AI-generated illustration

Dodo Payments, a Bengaluru-based payments company, is facing scrutiny after a dark web listing surfaced, allegedly contradicting the company's official statements about a recent data breach. On August 17, Dodo Payments informed its customers that an incident involving an internal analytics system did not expose critical data like API keys, passwords, or account credentials.

However, a review by MediaNama of a listing on the dark web describes a stolen dataset from the company that purportedly includes a wide range of data types. These reportedly include KYC verification requests, identity verification requests, bank verification requests, business phone numbers and verification, UBO requests, payout compliance requests, payout bank accounts, and additional verification requests, alongside fingerprint events containing user emails, client IPs, and thumbprint hashes.

In its disclosure, Dodo Payments stated, "Merchant API keys, dashboard passwords and account credentials are not stored in the affected system and were not accessed." Co-founder Rishabh Goel reiterated this on X, asserting that "No passwords, API keys, webhook secrets, card numbers, or stored payment tokens were involved." The company emphasized that the compromised system was a self-hosted Metabase deployment used solely for internal reporting, separate from payment processing systems.

The dark web listing, reportedly dated August 16, 2026, a day before Dodo Payments' public disclosure, claims the dataset contains approximately 60.8 GB across four ClickHouse databases and around 39.3 million rows. It specifies categories such as 'Internal API & auth,' allegedly including API keys and authentication tokens, and a 'Credentials' table purportedly sourced from Keycloak, an identity management system not mentioned by Dodo Payments.

MediaNama has reached out to Dodo Payments for confirmation or denial of the dark web claims and awaits a response. The publication notes that it has not independently verified the authenticity of the data on the dark website and acknowledges that threat actors may have an incentive to exaggerate the scope of a breach.

Original source: medianama.com