ISMS Copilot - Undue Stripe Charges Due to API incident – Incident details

All systems operational

Undue Stripe Charges Due to API incident

Resolved
Under maintenance
Started 17 days agoLasted about 4 hours

Affected

ISMS Copilot

Under maintenance from 12:00 PM to 3:32 PM, Operational from 3:32 PM to 6:32 PM

Updates
  • Update
    Update
    We've reviewed API configurations and took measures to make sure this can't occur again. We also removed the payment methods of past customers without active subscriptions to ensure they can't be charged in the future.
  • Resolved
    Resolved
    This incident has been resolved.
  • Monitoring
    Monitoring
    * _Initial Update (1 hour after incident)_: Identified unauthorized charges of customers via Stripe. Refunds initiated, and investigation into the root cause underway. * _Final Update (2 hours after incident)_: Incident contained, all refunds triggered, and ongoing investigation to strengthen API security.
  • Investigating
    Investigating
    An incicent affecting our API, causing Stripe to unexpectedly charge hundreds of current and past customers €163 each. All refunds have been triggered, and the incident is now contained. We are actively investigating how this attack bypassed configuration checks to prevent future occurrences. Our support team is progressively responding to hundreds of customer inquiries. Refunds are expected to process within 5 days, though this may vary depending on individual banks. We are deeply sorry for the inconvenience and are committed to ensuring this does not happen again.