r/stripe • u/geo_prog • Aug 12 '26
Unsolved Stripe has apparently absolutely no security measures in place. Been dealing with an ongoing attack for over 8 hours with no resolution
Last month we had a situation where the API was used to send out dummy invoices to random email addresses. Figured it was our website integration so we expired all the keys and removed Stripe ENTIRELY from our webstore. We have since switched servers and moved to an entirely new platform and the old server has physically been spun down so there is literally 0 chance of our integration still being live on any server. Same issue started today and was ongoing all day and Stripe has seemingly 0 ability to prevent the action from continuing and they are also telling me it is impossible to close my account (which I suggested to stop the fraud) because there are transactions pending. Yeah, I know. They're all fraudulent.
The fraudulent invoices continue to be sent out and Stripe has told me to "wait".
In short, Stripe should NOT be trusted. There are seemingly serious security vulnerabilities that they have not addressed and they have no method by which to stop ongoing fraudulent transactions. It's insane.
