Vercel Confirms Security Breach, Hacker Claims to Be Selling Stolen Data
Key point
A breach of Vercel's internal systems was confirmed, and a hacker claimed to be selling the data.
Details
Vercel has officially confirmed unauthorized access to internal systems and is currently investigating with incident response experts and law enforcement. The service itself was not affected, but the company stated that some customers were affected.
The starting point of the breach was a compromise of the Google Workspace OAuth app of third-party AI tool Context.ai. Through this path, a Vercel employee account was compromised, and it was explained that privilege escalation into the Vercel environment occurred from that account afterward.
The attacker enumerated non-sensitive environment variables to gain further access, and these variables were stored without at rest encryption applied. Vercel stores customers' sensitive environment variables fully encrypted at rest, but this incident revealed that management of variables classified as non-sensitive could act as a vulnerability.
On hacking forums and Telegram, a hacker claiming to be ShinyHunters claimed to be selling the following:
- access keys
- source code
- database data
- internal deployment access
- tokens including API keys
The hacker also presented Linear data as evidence and claimed to hold access to multiple employee accounts, and reportedly demanded a $2 million ransom. However, BleepingComputer was unable to independently verify the authenticity of the data and screenshots.
Vercel recommended the following to customers:
- Review environment variables
- Enable the sensitive environment variable feature if needed
- Perform secret rotation
The company also emphasized that the safety of open-source projects such as Next.js and Turbopack was not affected, and stated that it has deployed an environment variable overview and an improved management interface on the dashboard. IOCs were also disclosed, urging Google Workspace admins to check a specific OAuth client ID.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.