Breach report
Dodo Payments says Metabase flaw exposed merchant data; leak listing claims far more

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The Bengaluru payments firm says an attacker reached one internal analytics system. A dark-web listing claims 60.8 GB and 39.3 million rows. The claim is unverified.
What happened
Dodo Payments, a Bengaluru-based payments company, said on 17 August 2026 that it found unauthorised access to a self-hosted Metabase instance the day before. Metabase is a business-reporting tool; the company used it only for internal analytics, separate from payment processing. According to the company, the attacker used an SQL injection flaw in Metabase that bypassed authentication, so no Dodo Payments credential was needed. It says it contained the access within hours, upgraded to a patched release and revoked every session, token and key linked to the system.
Confirmed vs. claimed
Confirmed by Dodo Payments: merchant information held in the analytics system was accessed. The company says payment processing, full card numbers, merchant funds, API keys and account credentials were not affected, and it will contact affected merchants directly.
Claimed, unverified: MediaNama reported on 1 September that a dark-web listing dated 16 August claims about 60.8 GB across four databases and roughly 39.3 million rows, including KYC and bank-verification records and credentials. This conflicts with the company's account. MediaNama said it had not verified the data, and sellers often overstate what they hold.
Who is affected
Merchants that use Dodo Payments. The company has not said how many merchants, or which fields, were involved. If the listing is genuine, customers of those merchants could also be exposed, but that has not been shown.
What to do
- Merchants: rotate API keys, webhook secrets and dashboard passwords anyway. Dodo Payments calls this optional; it is cheap.
- Expect phishing that quotes your business name, KYC status or payout details. Verify any request to change bank details through the dashboard, not a link in an email.
- Turn on two-factor authentication for every payments and bank account.
- If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
- More steps: what to do after a data breach notice.
Sources
More breaches in India
- Bank of Baroda — 28 Jul 2026
- Reliance Infrastructure (Kudankulam project data) — 16 Jul 2026
- UMANG (MeitY government services app) — 14 Jul 2026
- National Testing Agency (CUET-UG 2026 candidate data) — 08 Jul 2026
- IDRBT (.bank.in domain registry) — 29 Jun 2026