Vercel data leak: CEO confirms internal breach linked to AI tool as hackers claim to sell stolen data for $2 million

Cloud development platform Vercel on Sunday (local time) confirmed a data breach that compromised its internal systems. Vercel CEO Guillermo Rauch disclosed details about the data breach in a post on X, where he also hinted that AI may have been used to accelerate the attack.

Vercel CEO confirms data breach

In his X post, Rauch explained that the breach originated when a Vercel employee’s Google Workspace account was compromised. He noted that the Vercel employee was using an AI platform called Context.ai, which was breached, and the attackers then used it to compromise the employee’s Google Workspace account.

“Through a series of manoeuvres that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments,” Rauch explained.

Rauch added that while Vercel stores all customer environment variables fully encrypted at rest, the platform does allow developers to designate certain environment variables as “non-sensitive.” The attackers were able to leverage this feature, using enumeration on these “non-sensitive” variables to gain further system access.

“We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel,” he added.

Rauch also noted that a ‘limited’ number of customers were affected by the attack. The company has reached out directly to the customers affected by the breach.

“All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitisation of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analysed our supply chain, ensuring Next.js, Turbopack, and our many open-source projects remain safe for our community,” he added.

Following its initial security advisory, Vercel has also updated its bulletin to explicitly advise Google Workspace administrators and account owners to check their systems for a specific compromised OAuth application linked to the third-party AI tool, BleepingComputer reported.

Hackers claim to be selling stolen data

The disclosure by Vercel comes shortly after a post on a hacking forum, under the moniker ‘ShinyHunters’, claimed to sell access to Vercel’s internal data.

According to the BleepingComputer report, the hacker claimed to be selling access keys, company source code, database data and internal deployments, specifically noting the inclusion of GitHub and NPM tokens. As proof of the breach, the attacker shared a text file containing 580 records of Vercel employee information, including names, email addresses, and account activity timestamps, along with a screenshot of an internal enterprise dashboard.

The hacking group also claimed in Telegram messages that it was in direct contact with Vercel to negotiate a $2 million ransom demand. The report, however, added that threat actors genuinely linked to the known ‘ShinyHunters’ extortion gang have denied any involvement in this specific Vercel incident.

Latest

Apple names John Ternus as next CEO as Tim Cook shifts role

Apple shifts focus to AI and hardware with new CEO

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

AI transforming journalism; women journos can turn tech shift into opportunities: Brijesh Singh

Indian-origin iLearning execs held in US over fake AI revenue fraud case

Two Indian-origin executives, Puthugramam “Harish” Chidambaran and Sayyed Farhan Ali “Farhan” Naqvi have been accused of running a multi-year fraud with

After Nord 6, OnePlus to launch Nord CE 6 and CE 6 Lite in India, key specs revealed

OnePlus Nord CE6 series is set to launch on May 7 in the Indian market. The lineup consists of two smartphones, the OnePlus Nord CE6 and the OnePlus Nord CE6 Li

I integrated Google Gemini into my daily workflow and saw real productivity gains

From email drafts to task management, I integrated Google Gemini into my daily workflow to test if it actually saves time. Here’s what worked, what didn’t,

Topics

Apple names John Ternus as next CEO as Tim Cook shifts role

Apple shifts focus to AI and hardware with new CEO

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action

Two Southwest Airlines planes came dangerously close in Nashville and had to take evasive action

I’m winning war by a lot: Trump claims amid uncertainty over Iran talks in Pakistan

US-Iran negotiations in Pakistan uncertain as Trump makes bold claims

Proud of myself: Tilak rejoices after maiden IPL hundred ends MI’s wait for victory

IPL 2026, GT vs MI: Tilak Varma smashed a brilliant unbeaten 101 off 45 balls to power Mumbai Indians to a 99-run win over Gujarat Titans and match MI’s faste

Not Hardik Pandya’s problem: MI captain hits back at critics over Bumrah first-over call

IPL 2026, GT vs MI: Back to winning ways after four defeats in a row, a relieved Mumbai Indians skipper Hardik Pandya took a dig at critics who had questioned h

Rick Perry’s Fermi Is Undermining the AI Energy Thesis

The Fermi Paradox asks why, given the vastness of the universe, there is no hard evidence of aliens. The Fermi Inc. paradox asks why, given seemingly insatiable

Digital Gold explained: Here’s all you need to know about cost, associated charges, risk and tax liability for the asset

If your investment in gold is not for personal use, there are other alternatives to choose when looking to invest in the asset instead of purchasing physical go
spot_img

Related Articles

Popular Categories

spot_imgspot_img