Breach tracker

Breach report

Dodo Payments says Metabase flaw exposed merchant data; leak listing claims far more

ConfirmedDisclosed Updated IndiaFinanceBy Vivek Kumar
Records UnknownCause Vulnerability
Conceptual illustration: A generic digital payment terminal connected to a transparent analytics grid with a small fracture and warning. Headline: DODO PAYMENTS CYBER INCIDENT.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The Bengaluru payments firm says an attacker reached one internal analytics system. A dark-web listing claims 60.8 GB and 39.3 million rows. The claim is unverified.

What happened

Dodo Payments, a Bengaluru-based payments company, said on 17 August 2026 that it found unauthorised access to a self-hosted Metabase instance the day before. Metabase is a business-reporting tool; the company used it only for internal analytics, separate from payment processing. According to the company, the attacker used an SQL injection flaw in Metabase that bypassed authentication, so no Dodo Payments credential was needed. It says it contained the access within hours, upgraded to a patched release and revoked every session, token and key linked to the system.

Confirmed vs. claimed

Confirmed by Dodo Payments: merchant information held in the analytics system was accessed. The company says payment processing, full card numbers, merchant funds, API keys and account credentials were not affected, and it will contact affected merchants directly.

Claimed, unverified: MediaNama reported on 1 September that a dark-web listing dated 16 August claims about 60.8 GB across four databases and roughly 39.3 million rows, including KYC and bank-verification records and credentials. This conflicts with the company's account. MediaNama said it had not verified the data, and sellers often overstate what they hold.

Who is affected

Merchants that use Dodo Payments. The company has not said how many merchants, or which fields, were involved. If the listing is genuine, customers of those merchants could also be exposed, but that has not been shown.

What to do

  • Merchants: rotate API keys, webhook secrets and dashboard passwords anyway. Dodo Payments calls this optional; it is cheap.
  • Expect phishing that quotes your business name, KYC status or payout details. Verify any request to change bank details through the dashboard, not a link in an email.
  • Turn on two-factor authentication for every payments and bank account.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
  • More steps: what to do after a data breach notice.

Sources

More breaches in India