Vercel April 2026 Security Incident
Key point
Vercel confirmed unauthorized access to internal systems, and some customers were affected.
Details
Vercel confirmed unauthorized access to some internal systems and disclosed a security incident.
The company stated that affected customers are limited, and it is currently working with breach response experts on investigation and remediation. It also said it has notified law enforcement and will update the notice as the investigation progresses.
The service itself was not affected, and the company said it is responding separately with affected customers. Customers were advised to:
- Review their environment variables
- Use the sensitive environment variable feature if needed
- Rotate secrets if suspicious
This notice came after a hacker claimed on a hacking forum to have breached Vercel and to be selling data. The attacker claimed to be ShinyHunters, but other threat actors recently linked to ShinyHunters-affiliated attacks reportedly denied any connection to this incident.
In the forum post, the attacker claimed to be selling access to the following data:
- access keys
- source code
- database data
- internal deployment environments and API keys
- some NPM tokens and GitHub tokens
The attacker also reportedly shared a text file containing 580 employee records and screenshots appearing to be from an internal Vercel Enterprise dashboard. However, as of the time of writing, BleepingComputer was unable to independently verify the authenticity of the data and screenshots.
The attacker also claimed to be in contact with Vercel via Telegram and that there had been a ransom negotiation of $2 million. Vercel is receiving additional inquiries, and if exposure of sensitive information or credentials is confirmed, a follow-up notice is possible.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.