Particle.news
Download on the App Store

Vercel Confirms Breach of Internal Systems Affecting Some Customers

Investigators have not verified the attacker’s data or the size of the breach.

Overview

  • Vercel disclosed unauthorized access to certain internal systems and said only a limited subset of customers were affected.
  • Company leaders brought in external incident response experts and notified law enforcement, and they said public services remain available.
  • The disclosure followed a forum post by a hacker claiming ties to ShinyHunters who advertised alleged access keys, source code, and database records for sale.
  • BleepingComputer reported the hacker also referenced a $2 million ransom in Telegram messages, and the outlet said it could not confirm the shared data or images.
  • Vercel advised impacted customers to review environment variables, use its sensitive variable feature, and rotate any exposed secrets, noting it has not specified which systems or how many accounts were affected.