Security1 distinct publisher3 min readPublished
The projects say Stripe cut the access off before the full email list left. In a country where supporting an "undesirable" organization carries five years, the addresses that did leave are enough to open a case.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Davayte's fix names the component. It disabled third-party integrations, rotated its access keys and notified the relevant European data protection authority [6]. The keys got rotated because what had worked for the intruder was a credential issued to software, not to a person.
That is the layer a small nonprofit does not staff. The WordPress site has an owner, usually whoever built it. The payment account has an owner, usually whoever does the books. The plugin between them holds a long-lived key, updates on the site's schedule if the site has one, and belongs to neither role. Both sides trust it, and neither one checks on it.
The evidence fits that reading. A read key against a processor's stored customer records returns metadata and cannot return a full card number or a cardholder name, which both projects say stayed put [4]. The shutoff also came from the processor's side, part way through an export [5], which is where account-level anomaly detection lives rather than anywhere on the WordPress host.
Keep the two Stripe stories apart. Early in August a hacker using the alias "Satanic" posted an archive said to hold data from 669 merchants and more than 1,000 access keys [11]. That averages roughly 1.5 keys per merchant [12], the profile of estates where each integration gets its own credential instead of one login per company. Whether Stripe itself was breached there is unclear [13], and The Bell reports the archive's records stop on June 1, which places a mid-August theft outside that dataset [14]. Broader targeting of Stripe merchants has been reported, with no confirmed link to these two projects [22]. Davayte has asked Stripe whether other customers saw similar activity [15]. Stripe did not respond to The Record's request for comment [16].
The gap between how valuable this data is and how little attention the connector holding it gets comes down to scale. Davayte launched in February 2024 with backing from independent outlets including Meduza and TV Rain, and says it raised more than $437,000 in 2024 [17]. You Are Not Alone reports around $1.4 million over its first three years [18], an average near $467,000 a year [19], and assistance to roughly 800 political prisoners and their relatives [20]. Those are mid-sized nonprofit donor lists sitting behind budgets that fund food, medicine and legal fees.
The controls that would have capped this are cheap. A key scoped to what an auction actually needs, plus a rotation date that does not wait for an incident, costs attention rather than money. What this case actually charges for is a decision about ownership, made before the next auction instead of during the next intrusion.
Ranked by verification strength, evidence, and original report placement.
Stripe blocked the unauthorized access before the attackers could download the entire database of donor email addresses, and found no evidence of fraudulent transactions involving the projects' accounts, according to the projects.
Two Russian fundraising projects, Davayte and You Are Not Alone, disclosed on Tuesday that hackers gained access to payment accounts they used, in attacks that occurred in mid-August; Davayte raises money for civilians in Ukraine affected by Russia's invasion and You Are Not Alone supports Russian political prisoners and their families.
Both projects said the incidents involved the same entry point: an integration between payment processor Stripe and WooCommerce, an open-source e-commerce plugin for WordPress, that the projects had used to conduct online auctions.
The attackers obtained email addresses belonging to some donors and, in certain cases, the last four digits of their payment cards and information about the banks that issued them.
Full card numbers, cardholders' names and details about individual donations were not exposed, the projects said.
Davayte has since disabled third-party integrations, rotated its access keys and notified the relevant European data protection authority.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Six MariaDB versions, one real difference: the only reason to leave 10.6 is the July 2026 clock1 distinct publisher
build
WooCommerce catalog mode: the price you hid is still sitting in eight places1 distinct publisher
build
Plugin page caches spend a PHP-FPM worker slot on every cache hit1 distinct publisher
product
PayPal stopped saying no. Payments teams should now plan for a Stripe-owned checkout rail3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Victim statements, one newsroom, a silent processor
Trace any load-carrying fact back and it ends at one of the two projects. They describe the entry point, the data taken, the data spared, and even Stripe's own findings about blocked access and absent fraud. Recorded Future News is the only outlet in our coverage, and Stripe declined to comment, so the party with the logs never speaks. The one piece of outside examination — The Bell reading the leaked archive's records as ending June 1 — arrives second-hand. The facts are specific and internally consistent; nobody independent has checked them.
Two confirmed merchants, unmeasured blast radius
Concretely confirmed: two organisations, one shared integration, one remediation sequence, one changed donor-payment policy. Everything beyond that is open. Davayte had to ask Stripe whether other customers saw the same activity, which tells you nobody outside the processor can size this. The circulating archive of alleged merchant keys hints at a wider pattern but has been timeline-excluded from these two breaches, and the reporting refuses to join them.
If anything, undersold
The restraint runs the other way here. The archive is labelled alleged, the Stripe breach question is left open, the link to wider merchant attacks is called unconfirmed, and attribution stays genuinely unresolved between criminals and security services. Meanwhile the consequence that matters is stated once and left there: an email address, in this legal context, is enough to expose a donor to a five-year sentence. Read the guidance closely and it goes further than the piece says — with Russian-issued cards never accepted and foreign cards now discouraged, a donor inside Russia has no card route left at all.
The breached parties write the reassuring half
The projects have two audiences at once: donors they need to keep, and donors they must warn. That shows in the shape of their disclosure — the reassurances (no full card numbers, no names, no per-donation detail, download interrupted, no fraud) are theirs, and unverifiable. To their credit the same statements carry advice that suppresses their own domestic fundraising, which is not what a purely defensive disclosure looks like. Stripe's silence is the other pull: the party best placed to size the problem has every reason to say nothing while an archive of alleged merchant keys circulates.
Firm on what happened, blind on how far
That two charities lost donor emails through a Stripe-WooCommerce path in mid-August, and why that is dangerous under Russian law, is solid enough to act on. Everything about magnitude — how many addresses, how the keys were exposed, which other merchants, whether a state actor was involved — rests on one newsroom relaying statements from parties who say themselves they do not yet know.