Vercel says its internal systems were accessed via a compromised third-party AI tool, after a user with a ShinyHunters handle claimed a breach on BreachForums
Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data.
BleepingComputer Lawrence Abrams
Related Coverage
- Vercel April 2026 security incident Vercel
- Vercel just confirmed an internal breach, and your non-sensitive env vars may be exposed XDA Developers · Simon Batt
- Vercel Says Internal Systems Hit in Breach Decipher · Dennis Fisher
- Vercel April 2026 security incident Hacker News
- Vercel says internal systems hit in breach Hacker News
- Cloud development platform Vercel was hacked The Verge · Terrence O'Brien
- Vercel confirms security incident as hackers claim to sell internal access CyberInsider · Amar Ćemanović
- Web3 hosting backbone Vercel confirms breach as supposed hacker demands $2 million ransom The Block · Zack Abrams
Discussion
-
@diffekey
Alex
on x
Vercel has reportedly been breached by ShinyHunters. As of now, nobody else appears to be posting about this, so I'm sharing what I have. Here is the information I've gathered, along with screenshots provided by ShinyHunters. #cybernews #shinyhunters #breach #vercel #news [image]
-
@k1rallik
BuBbliK
on x
VERCEL GOT HACKED ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums here's why every developer should care: - they have NPM tokens and GitHub tokens - Vercel owns Next.js - 6 million weekly downloads - one [ima…
-
@theo
@theo
on x
I have reason to believe this is credible. If you are using Vercel, it's a good idea to roll your secrets and env vars.
-
@darkwebinformer
@darkwebinformer
on x
‼️ Vercel has allegedly been breached by ShinyHunters, with a ransom demand of $2,000,000. https://vercel.com/... [image]
-
@ohryansbelt
Ryan
on x
Someone on BreachForums claiming to be ShinyHunters is selling what they say is Vercel's internal database, access keys, and source code for $2M. ShinyHunters is a black-hat hacker group known for a significant number of breaches and a “pay or leak” model. Vercel has confirmed a …
-
@shiri_shh
Shirish
on x
VERCEL just got breached. They're selling internal DB + employee accounts + GitHub/NPM tokens for $2M on BreachForums. looks like someone got early access to Claude Mythos 💀 [image]
-
@zackwhittaker.com
Zack Whittaker
on bluesky
In other Sunday news, cloud app giant Vercel says it's been hacked that involved “unauthorized access to certain internal Vercel systems.” Some customers' affected, though it's not clear if any data was taken. Doesn't say what the security incident is, though, exactly. Unclear…
-
@vercel
@vercel
on x
Our investigation has revealed that the incident originated from a third-party AI tool with hundreds of users whose Google Workspace OAuth app was compromised. We recommend that Google Workspace Administrators check for usage of this app immediately. https://vercel.com/...