Data breach
DodoPayments
- Records
- 534,481
- Breach date
- 15 August 2026Estimated
- Added
- 2 September 2026
What was exposed
5 types of data
- Email addresses534,481
- Names148,532
- Phone numbers15,517
- Dates of birth14,465
- Street addresses2,498
About this breach
DodoPayments, a Bengaluru-based payments company that handles cross-border billing for software startups, has been listed on the leak site of the group calling itself direwolf, and our investigation team has indexed a dataset tied to the incident containing 534,481 rows. The attackers exposed a flaw in an internal reporting tool the company uses, not its payment processing systems, according to a company statement. The two accounts of what happened differ in scale and in severity, and the company has disputed the dark web version of events.
Breach Timeline
August 15, 2026: The direwolf group listed DodoPayments on its leak site. Ransomware.live recorded the listing at 20:27 UTC that day and logged an estimated attack date of August 15.
August 16, 2026: A dark web listing dated this day claimed the stolen dataset totaled roughly 60.8 GB across four ClickHouse databases and about 39.3 million rows, according to reporting by Medianama. Dodo Payments says it became aware of the incident the same day and contained unauthorized access within hours.
August 17, 2026: Dodo Payments published a security notice explaining that an intruder exploited CVE-2026-72898, an SQL injection flaw in Metabase, a third-party open-source reporting tool, to reach an internal analytics system.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, names, dates of birth, phone numbers, and street addresses. Email addresses appear in all 534,481 indexed rows, names in 148,532, dates of birth in 14,465, phone numbers in 15,517, and street addresses in 2,498, according to our investigation team's review of the dataset.
The dark web listing described by Medianama claims a far larger haul, roughly 39.3 million rows, but those figures have not been independently verified and the company has not confirmed them.
Not every individual is affected by every type of data listed here.
Dodo Payments' own notice states that information relating to some of its merchants was involved and that it is still determining the specific data categories and the individuals affected. The company says payment processing systems, full card numbers, merchant funds, account credentials, and API keys were not accessed, and that its PCI DSS certification is unaffected.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and names are enough to fuel targeted phishing, in which criminals send convincing messages that reference a real service the recipient uses. Because Dodo Payments is a payments platform, a phishing email that appears to come from it could carry extra weight with merchants.
Dates of birth and phone numbers make identity-based scams and account takeover attempts more persuasive, since attackers can answer basic verification questions. Street addresses, though present in a smaller share of records, add another detail criminals can use to appear legitimate. Anyone whose data appears in the breach should treat unexpected emails or calls about their Dodo Payments account with suspicion.
What Is DodoPayments Doing in Response?
Dodo Payments says it learned of the incident on August 16, 2026, and contained the access within hours by revoking every session, token, and key tied to the affected system and upgrading Metabase to a patched release. The company states that no destructive software was involved and that no service disruption occurred. It says it will contact affected merchants directly and has asked people with questions to email privacy@dodopayments.com. Co-founder Rishabh Goel publicly stated that no passwords, API keys, webhook secrets, card numbers, or stored payment tokens were involved, according to Medianama.
What Should You Do If You Were Affected?
If you are a Dodo Payments merchant or customer, watch your email for messages claiming to come from the company and verify any request through official channels. The company says it will never ask for passwords, API keys, or one-time codes by email or phone, and that official incident communication will come only from an @dodopayments.com address. Consider rotating your Dodo Payments API keys and passwords as a precaution, even though the company says credentials were not affected. Enable multi-factor authentication wherever the service offers it, and be cautious with links in payment-related emails over the coming months.
In the news
- Dodo Payments security incident noticedodopayments.com (opens in a new tab)
- Medianama: Dodo Payments breach disclosure disputed by dark web listingmedianama.com (opens in a new tab)
- Ransomware.live: Victim listing for DodoPaymentsransomware.live (opens in a new tab)
- BreachSense: Dodo Payments Data Breach in 2026breachsense.com (opens in a new tab)
