The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Checkout.com said in November 2025 that ShinyHunters claimed to have stolen company-related data and demanded a ransom. The payment company refused to pay, saying it would instead donate the requested amount to cybersecurity research at Carnegie Mellon University and the University of Oxford Cyber Security Center. Checkout.com said the exposure came from a poorly decommissioned, third-party cloud file-storage system used in 2020 and earlier—not its live payment-processing platform.
What happened
Checkout.com disclosed the incident in a statement dated around November 12, 2025, with major reports following on November 14. The company said ShinyHunters contacted it, claimed to possess Checkout.com-related data and demanded payment. An investigation traced the exposed material to a legacy third-party cloud file-storage system that had been used for internal operational documents and merchant-onboarding materials from 2020 and prior years.
Checkout.com’s chief technology officer, Mariano Albera, acknowledged that the system had not been decommissioned properly, calling that a company mistake. The company said it was identifying affected parties, working with law enforcement and engaging relevant regulators. Checkout.com’s statement contains its first-party account.
Was Checkout.com’s payment platform hacked?
Checkout.com said its active payment-processing platform was not affected. It also said the attackers did not access merchant funds or card numbers. That makes this a breach of a retired storage environment and an extortion attempt, not evidence that Checkout.com’s live payment rails were compromised.
Recommended Free Tools
#1 Best Overall
Those are the company’s reported findings, not proof that no merchant-related information was exposed. The company acknowledged that documents and onboarding materials connected to merchants were in the legacy system.
What information may have been exposed?
Public disclosures describe categories, not a complete field-by-field inventory. Potentially involved material included:
- Internal operational documents.
- Merchant-onboarding materials.
- Information connected to current and potentially former merchants.
- Files dating from 2020 and earlier.
The available statements do not establish whether passwords, payment-card data, bank details, Social Security numbers, authentication tokens or other specific personal-data categories were included. Checkout.com also has not publicly identified the storage provider or the initial access method. BleepingComputer’s coverage notes those omissions.
How many merchants were affected?
Checkout.com estimated that fewer than 25% of its current merchant base could be affected. That is a proportion, not a confirmed number of merchants or records, and it does not necessarily account for former customers whose information remained in the old system. No final record count was included in the reviewed public statements.
Rank #3
Who are ShinyHunters?
Checkout.com identified the group that contacted it as ShinyHunters, a known data-theft and extortion operation. Reporting has associated the broader ShinyHunters ecosystem with phishing, OAuth abuse, social engineering and data-extortion campaigns. Those associations do not prove that any one of those techniques was used against Checkout.com. The company has not publicly disclosed the intrusion vector, and the group’s claim of possessing data should be kept distinct from independently verified details.
Why Checkout.com refused to pay
The company said it would not be extorted and would redirect the requested ransom amount to research intended to combat cybercrime. It named Carnegie Mellon University and the University of Oxford Cyber Security Center as recipients. The ransom amount, payment date, recipient program and proof that a transfer was completed were not disclosed in the sources reviewed.
Rank #4
The case for refusal
- Payment cannot guarantee that criminals will delete data or keep it confidential.
- Money can finance further criminal activity and create incentives for additional attacks.
- Redirecting the demand toward security research gives the decision a constructive public purpose.
The limits of the decision
- Refusal does not undo unauthorized access or prevent publication and resale.
- Notification, regulatory, contractual, litigation and remediation costs can continue even without a ransom payment.
- A donation cannot replace forensic work, merchant support or stronger access controls.
- The choice may look different when operational systems or safety-critical data are at immediate risk; it is not a universal rule for every incident.
Reporting by The Stack said no malware was deployed. The safest description is therefore a data breach and extortion attempt, rather than assuming file-encrypting ransomware. Headlines calling it a ransomware incident should make that qualification clear.
The legacy-system lesson
“Retired” does not mean harmless. An old file store may still contain valuable merchant information, remain accessible through forgotten accounts or vendor links, and escape routine monitoring. Decommissioning should be a documented control, not simply the moment a business stops using a service.
Best Value
A complete retirement checklist
- Inventory files, owners, integrations and third-party accounts before closing a service.
- Apply a retention schedule based on business, legal and regulatory requirements; securely delete data that no longer has a purpose.
- Revoke user and service credentials, tokens, API keys and sharing links.
- Remove access permissions and confirm that backups, replicas and exports are handled under the same policy.
- Obtain vendor-offboarding confirmation and retain evidence of deletion.
- Record a named owner for every remaining archive and review it periodically.
The same controls apply to merchants’ own document repositories. Customer onboarding files should not remain indefinitely in an unowned storage account merely because the associated product or project has ended.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected merchants should do
- Watch for a direct notice from Checkout.com and verify it through an established company contact.
- Treat unsolicited follow-up emails, calls or document requests referring to this incident as potential phishing; do not use links or phone numbers supplied in an unexpected message.
- Ask Checkout.com which categories of your information were involved, whether you are among the affected parties and what action is required.
- Review old onboarding documents and rotate any credentials or secrets that may have been stored in legacy files, even though the public statement did not say credentials were exposed.
- Review your own third-party storage retention, access-review and vendor-offboarding procedures.
These precautions do not establish that a particular merchant’s systems or credentials were compromised; they reduce the risk of follow-on fraud while notifications are clarified.
What remains unknown
- The exact number of records and affected merchants.
- The specific fields contained in the exposed files.
- The identity of the storage provider.
- The initial access vector.
- The ransom amount.
- Whether and when the promised donation was completed.
- Whether ShinyHunters published or sold the data.
Timeline and source notes
| Date | What is documented |
|---|---|
| 2020 and earlier | The legacy system held internal and merchant-onboarding materials from this period. |
| November 12, 2025 (approximately) | Checkout.com’s first-party incident statement was dated around this date. |
| November 14, 2025 | Major security-news reports described the disclosure and ransom refusal. |
| After disclosure | Checkout.com said it was identifying affected parties and coordinating with law enforcement and regulators; the public materials reviewed do not provide a final exposure count. |
Independent coverage from SecurityWeek and TechRadar Pro broadly matches the distinction between the legacy file store and the live payment platform. Checkout.com also published a parallel German-language statement at its site.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




