Security incident tracker

See what failed.
See what was affected.

Security claims need dates, boundaries, and sources. This tracker separates confirmed incidents from disclosed vulnerabilities and routine outages.

Records
8
verified in this scan
Catalog-linked
3
provider or integration
Window
6 mo
Mar 1, 2026–Sep 1, 2026
Reviewed
Sep 1, 2026
next review Oct 1, 2026
Coverage boundary

This is a public-disclosure record, not a claim that every incident is known. No entry does not prove that a provider had no security problem.

How records qualify →
March–September 2026 scan

Publicly documented records.

The date shown is the incident date when known. Otherwise, it is the first reliable disclosure or advisory date.

01 Incident date
Confirmed incident Internal analytics system Catalog provider
Dodo Payments

Attackers reached an internal Metabase deployment

Provider profile →

Dodo Payments said attackers exploited CVE-2026-72898 against a self-hosted Metabase system used for internal reporting. The company contained the access and said its investigation remained in progress.

Observed impact
Dodo said it would contact every affected merchant directly. Its public update did not quantify the merchants or reporting data involved.
Reported boundary
Dodo reported no disruption, funds movement, payment or cardholder data exposure, or exposure of passwords, API keys, webhook secrets, card numbers, or stored payment tokens.
Current status
Contained; investigation ongoing
What to do

Watch for direct notice from Dodo and treat unexpected requests for credentials or one-time codes as phishing.

02 Disclosure date
Exploited vulnerability Self-hosted payment server Adjacent payment infrastructure
BTCPay Server

A critical flaw exposed LND administrator credentials

BTCPay Server confirmed that attackers exploited a vulnerability affecting deployments connected to LND. Attackers could obtain LND admin macaroon files, take control of nodes, and move funds.

Observed impact
BTCPay confirmed that users were affected and funds were stolen. The project did not publish a total loss in the cited updates.
Reported boundary
The project said other Lightning implementations and deployments without Lightning were not exposed to this LND credential risk. BTCPay on-chain wallets were not affected.
Current status
Patched in BTCPay Server 2.4.2
What to do

LND operators should update, confirm LND 0.21.1, review node activity, and rotate credentials for access paths they manage separately.

03 Incident date
Confirmed incident Operational wallets and production environment Adjacent payment infrastructure
Triple-A

Social engineering led to unauthorized wallet withdrawals

Triple-A said a targeted social-engineering attack compromised an engineering team member's credentials. The attacker escalated privileges, deployed malware, accessed production databases, abused API credentials, and withdrew company-owned digital assets.

Observed impact
Triple-A absorbed the loss from its own treasury assets. It did not publish the amount in the cited postmortem.
Reported boundary
Triple-A said client funds, transactions, settlements, other regulated entities, and regional operations were not affected. Services were restored about three hours after detection.
Current status
Contained; asset tracing and investigation ongoing
What to do

No merchant remediation was published. Merchants can review continuity plans for crypto-payment rails and monitor Triple-A's investigation updates.

04 Initial disclosure date
Confirmed data exfiltration Subsidiary cloud account Adjacent payment infrastructure
Nayax

Attackers exfiltrated document and transaction backups

Nayax reported unauthorized access to a subsidiary cloud account. Its follow-up said the exfiltrated material included scanned-document backups, business information, and mainly payment-transaction record backups.

Observed impact
The exact scope and contents remained under investigation in the July 14 update. Nayax rejected the attacker's extortion demand.
Reported boundary
Nayax said production and core payment systems were not affected. It said the records did not include cardholder names, CVV values, or identity information, and safeguarded customer funds were untouched.
Current status
Unauthorized access removed; investigation ongoing
What to do

Monitor Nayax notices for any scope change and follow direct instructions if the company identifies affected records tied to your business.

05 CVE publication date
Disclosed vulnerability Hosted application access control Catalog provider
Gumroad

A seller could change access to another seller's purchases

Provider profile →

CVE-2026-59805 describes missing ownership checks in Gumroad's PurchasesController. An authenticated seller could revoke or restore buyer access to products owned by another seller.

Observed impact
The flaw affected purchase-access integrity. The NVD record did not document known exploitation or data exposure.
Reported boundary
The cited record does not describe access to card data, account credentials, payouts, or the contents of purchased files.
Current status
Fixed in release v2026.07.06.2
What to do

Gumroad hosts the service, so sellers do not patch it themselves. Keep fulfillment records if purchase access changes unexpectedly.

06 Advisory publication date
Integration vulnerabilities Sylius MolliePlugin Catalog-provider integration
Mollie / Sylius

Webhook and order checks allowed payment forgery and data exposure

Provider profile →

Two Sylius MolliePlugin advisories described missing authorization checks. One could mark a target order paid using a different valid Mollie payment. The other could expose order tokens, customer names, and email addresses through sequential order IDs.

Observed impact
The advisories describe possible unpaid fulfillment, customer-data exposure, and unauthenticated denial of service. They do not document confirmed exploitation.
Reported boundary
These flaws were in the Sylius integration, not Mollie's payment platform. Stores that do not run the affected plugin are outside this record's scope.
Current status
Patched releases available
What to do

Sylius merchants using MolliePlugin should follow both GitHub advisories and update to a patched release. Abandoned predecessor packages do not receive fixes.

07 Incident start date
Confirmed cyber event Accounts and Pix transfers Adjacent payment infrastructure
MagaluPay

A cyber event disrupted access to customer funds

MagaluPay confirmed to Finsiders Brasil that a cyber event caused service instability. Customers reported being unable to access accounts, make Pix transfers, or reach support for several days.

Observed impact
The company did not disclose the attack method, its financial cost, or a complete restoration timeline in the cited report.
Reported boundary
MagaluPay told the publication that customers had no personal-data exposure or financial loss. The public report did not provide independent technical findings.
Current status
Company response published; technical detail limited
What to do

Affected customers should reconcile missed or delayed transfers and retain provider notices if the disruption caused a payment deadline to be missed.

08 First disruption date
Security-related disruption Payment-service availability Adjacent payment infrastructure
GMO Payment Gateway

Abnormal traffic and DDoS controls delayed payment services

GMO Payment Gateway said abnormal requests from specific merchant systems exceeded connection limits and activated DDoS detection. Multiple payment services were difficult to use across incidents from May 27 through May 30.

Observed impact
The incidents caused processing delays across the PG Multi-Payment Service and other payment services. GMO did not publish a transaction count in the cited notice.
Reported boundary
GMO said it found no unauthorized system intrusion or information leakage.
Current status
Resolved after capacity, traffic-control, and DDoS-detection changes
What to do

Merchants should reconcile affected transactions before retrying them and preserve idempotency when recovering from payment timeouts.

Inclusion method

Facts first.
Unknowns stay visible.

01

Require a reliable public record.

Provider disclosures, regulatory filings, government vulnerability records, and project security advisories come first. A direct company statement reported by the press can qualify when no primary notice exists.

02

Separate incidents from possibilities.

A vulnerability is not labeled exploited unless the source confirms exploitation. A provider integration is not presented as a breach of the provider platform.

03

Record both impact and boundary.

What was not affected matters. We preserve the source's limits instead of turning a narrow event into a platform-wide claim.

04

Exclude unsupported claims.

Threat-actor posts, rumors, merchant account disputes, ordinary fraud, and unexplained status-page outages do not qualify without corroborating evidence.

Review cadence

This ledger is meant to change.

The next scheduled review is October 1, 2026. Earlier updates are added when a provider changes an incident's scope, impact, remediation, or investigation status.