Vercel data leak: CEO confirms internal breach linked to AI tool as hackers claim to sell stolen data for $2 million

7 hours ago 2
ARTICLE AD BOX

Vercel has confirmed a data breach affecting its internal systems and attributed it to employee's Google Workspace account linked to an AI tool.

Vercel has confirmed a data leakVercel has confirmed a data leak(AI generated image)

Cloud development platform Vercel has confirmed a data breach that compromised its internal systems. Vercel CEO Guillermo Rauch disclosed details about the data breach in a post on X (formerly Twitter), where he also hinted that AI may have been used to accelerate the attack.

Vercel CEO confirms data breach:

In his X post, Rauch explained that the breach originated when a Vercel employee's Google Workspace account was compromised. He noted that the Vercel employee was using an AI platform called Context.ai, which got breached, and the attackers then used it to compromise the employee's Google Workspace account.

“Through a series of manoeuvres that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments,” Rauch explained.

Rauch noted that while Vercel stores all customer environment variables fully encrypted at rest, the platform does allow developers to designate certain environment variables as "non-sensitive." The attackers were able to leverage this feature, using enumeration on these “non-sensitive” variables to gain further system access.

“We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel,” he added.

Rauch also noted that a ‘limited’ number of customers were affected by the attack. The company has reached out directly to the customers affected by the breach.

“All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitisation of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analysed our supply chain, ensuring Next.js, Turbopack, and our many open-source projects remain safe for our community,” he added.

Following its initial security advisory, Vercel has also updated its bulletin to explicitly advise Google Workspace administrators and account owners to check their systems for a specific compromised OAuth application linked to the third-party AI tool, BleepingComputer reported.

Hackers claim to be selling stolen data:

The disclosure by Vercel comes shortly after a post on a hacking forum, under the moniker "ShinyHunters", claimed to sell access to Vercel's internal data.

According to the BleepingComputer report, the hacker claimed to be selling access keys, company source code, database data, and internal deployments, specifically noting the inclusion of GitHub and NPM tokens. As proof of the breach, the attacker shared a text file containing 580 data records of Vercel employee information, including names, email addresses, and account activity timestamps, alongside a screenshot of an internal enterprise dashboard.

The hacking group also claimed in Telegram messages to be in direct contact with Vercel to negotiate a $2 million ransom demand. The report, however, noted that threat actors genuinely linked to the known ShinyHunters extortion gang have denied any involvement in this specific Vercel incident.

About the Author

Aman Gupta

Aman Gupta is a Digital Content Producer at LiveMint with over 3.5 years of experience covering the technology landscape. He specializes in artificial intelligence and consumer technology, reporting on everything from the ethical debates around AI models to shifts in the smartphone market. <br> His reporting is grounded in first-hand testing, independent analysis, and a focus on how technology impacts everyday users. He holds a PG Diploma in Radio and Television Journalism from the Indian Institute of Mass Communication, Delhi (Class of 2022). <br> Outside the newsroom, he spends his time reading biographies, hunting for the perfect coffee beans, or planning his next trip. <br><br> You can find Aman on <a href="https://www.linkedin.com/in/aman-gupta-894180214">LinkedIn</a> and on X at <a href="https://x.com/nobugsfound">@nobugsfound</a>, or reach him via email at <a href="aman.gupta@htdigital.in">aman.gupta@htdigital.in</a>.

Read Entire Article