HackMyIP
← Back to News
2026-09-02 The Record

Stripe-WooCommerce Breach Exposes Donor Data from Russian Charities

Data BreachSupply ChainVulnerability

An unknown threat actor compromised the payment infrastructure of two Russian fundraising projects—Davayte and You Are Not Alone—in mid-August, exposing donor email addresses and partial payment card information. Both initiatives disclosed the incidents Tuesday, revealing that the attacks exploited a common entry point: an integration between payment processor Stripe and WooCommerce, the open-source e-commerce plugin for WordPress, which the projects had used to host online auctions. Stripe blocked the unauthorized access before the attackers could exfiltrate the full donor email database, and no fraudulent transactions have been linked to the breach so far.

The attackers obtained email addresses from a subset of donors and, in some cases, the last four digits of their payment cards along with issuing bank details. Full card numbers, cardholder names, and individual donation records were not compromised. In response, Davayte disabled all third-party integrations, rotated its access keys, and notified the relevant European data protection authority. You Are Not Alone stated it is still investigating whether the breach was the work of ordinary cybercriminals or Russian security services. The incidents come amid broader reports of threat actors targeting Stripe merchants across multiple sectors, though no confirmed link to those campaigns has been established.

Davayte, launched in February 2024 by independent Russian media outlets including Meduza and TV Rain, raised more than $437,000 in 2024 to provide humanitarian aid to Ukrainians affected by Russia's invasion. You Are Not Alone, organized by independent media and opposition groups since 2023, has collected around $1.4 million over three years to support roughly 800 Russian political prisoners and their families with food, medicine, legal aid, and prison account deposits. Because Russian authorities have designated both parent organizations as "undesirable," donating to them can carry a prison sentence of up to five years under Russian law—making any leaked donor data particularly sensitive. Donors who suspect their information may be exposed can use an email breach checker to verify whether their address appears in known leaks, while organizations relying on WordPress-WooCommerce payment integrations should immediately audit their API keys and run a comprehensive privacy checkup to identify exposed endpoints. Site administrators should also validate their TLS configuration with an SSL/TLS checker to ensure payment data in transit remains properly encrypted.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →