ISMS Copilot - Undue Stripe Charges Due to API incident – Incident details
All systems operational
Undue Stripe Charges Due to API incident
Resolved
Under maintenance
Started 17 days agoLasted about 4 hours
Affected
ISMS Copilot
Under maintenance from 12:00 PM to 3:32 PM, Operational from 3:32 PM to 6:32 PM
Updates
Update
Update
We've reviewed API configurations and took measures to make sure this can't occur again. We also removed the payment methods of past customers without active subscriptions to ensure they can't be charged in the future.
Resolved
Resolved
This incident has been resolved.
Monitoring
Monitoring
* _Initial Update (1 hour after incident)_: Identified unauthorized charges of customers via Stripe. Refunds initiated, and investigation into the root cause underway.
* _Final Update (2 hours after incident)_: Incident contained, all refunds triggered, and ongoing investigation to strengthen API security.
Investigating
Investigating
An incicent affecting our API, causing Stripe to unexpectedly charge hundreds of current and past customers €163 each. All refunds have been triggered, and the incident is now contained. We are actively investigating how this attack bypassed configuration checks to prevent future occurrences. Our support team is progressively responding to hundreds of customer inquiries. Refunds are expected to process within 5 days, though this may vary depending on individual banks. We are deeply sorry for the inconvenience and are committed to ensuring this does not happen again.