2025 Checkout.com — ShinyHunters legacy cloud storage breach
Data compromised
Internal operational documents, merchant onboarding materials
Technical writeup
Checkout.com disclosed breach Nov 2025 after ShinyHunters extortion attempt. Unauthorized access to legacy third-party cloud file storage not used since 2020, improperly decommissioned. Exposed: internal operational docs, merchant onboarding materials (2020 and earlier). Less than 25% of current merchants affected. Payment processing, card data, transaction data not compromised. Company refused ransom; donated equivalent to CMU and Oxford for cyber research.
Root cause
Legacy cloud storage not decommissioned; ShinyHunters access