2026 GoCardless API leak — customer PII and payments
Data compromised
Full names, email addresses, UK residential addresses, language preferences, bank mandate details, subscription plans, payment transaction histories
Technical writeup
UK-based meditation and wellness platform Beeja Meditation allegedly compromised after a live GoCardless API token was leaked. Unauthorized read-only access to internal customer and financial records. Breach reportedly occurred February 17, 2026.
Root cause
Leaked GoCardless API token