Skip to main content
Mallory
Back to stories
breach-disclosure-notificationunderground-data-leakleaked-secret-api-keyransomware-group-operation

Vercel Confirms Breach After Threat Actor Offers Alleged Stolen Data for Sale

Updated 7d agoFirst seen Apr 19, 202632 sources

Vercel confirmed a security incident involving unauthorized access to certain internal systems after a threat actor using the name ShinyHunters claimed to be selling allegedly stolen company data on a hacking forum. The company said only a limited subset of customers was affected, its services remain operational, and it has engaged incident response experts, notified law enforcement, and is working directly with impacted customers.

The actor claimed the stolen data included access keys, source code, database data, internal deployment access, and API keys, and shared a text file with 580 employee-related records along with a screenshot purportedly showing an internal Vercel Enterprise dashboard. Vercel advised customers to review environment variables and rotate secrets if necessary, while the authenticity of the leaked materials and the attribution to ShinyHunters remained unverified; the actor also claimed on Telegram that a $2 million ransom demand had been discussed with the company.

Share:
Vercel Confirms Breach After Threat Actor Offers Alleged Stolen Data for Sale
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the earliest known activity through the most recent confirmed update.

10 EVENTS
Feb 1, 20264mo ago

Context.ai employee infected with Lumma Stealer in February

Vercel said the intrusion chain began when a Context.ai employee was infected with Lumma Stealer malware in February, reportedly via malware disguised as Roblox cheats. The infection allegedly led to compromise of Context.ai’s AWS environment and OAuth tokens, including one tied to a Vercel employee’s Google Workspace account.

Vercel's security breach started with malware disguised as Roblox cheats | CyberScoop
Mar 1, 20263mo ago

Context AI confirms March breach of Office Suite OAuth app

Context AI said its Context AI Office Suite application was breached in March and that attackers likely compromised OAuth tokens for some consumer users. The disclosure provides upstream context for how the Vercel employee account compromise may have occurred.

App host Vercel says it was hacked and customer data stolen | TechCrunch
Apr 19, 202629d ago

Threat actor advertises alleged Vercel data for sale

A threat actor using the name "ShinyHunters" posted on a hacking forum claiming to sell allegedly stolen Vercel data, including access keys, source code, database data, internal deployment access, and API keys. The actor also shared a text file with 580 employee-related records and a screenshot purportedly showing an internal Vercel Enterprise dashboard, though the materials were not independently verified.

Attacker claims $2 million ransom talks with Vercel

The same threat actor claimed on Telegram that they had discussed a $2 million ransom demand with Vercel. Attribution remained uncertain because actors linked to recent ShinyHunters-associated attacks reportedly denied involvement in this incident.

Vercel confirms security incident affecting internal systems

Vercel disclosed unauthorized access to certain internal systems and said only a limited subset of customers was affected while its services remained operational. The company said it was investigating the breach, engaged incident response experts, notified law enforcement, and advised impacted customers to review environment variables and rotate secrets if necessary.

Apr 20, 202628d ago

Vercel links breach to compromised OAuth app and Context.ai account access

Vercel said the intrusion began when attackers abused a malicious or compromised Google Workspace OAuth app tied to a Vercel employee's use of third-party AI tool Context.ai, allowing access to the employee's Google Workspace account and pivoting into select environments. The company also published the OAuth app identifier as an indicator of compromise and said Mandiant was assisting the investigation.

Vercel Confirms Data Breach - Hackers Claim Access to Internal Systems
Apr 21, 202627d ago

Vercel says npm packages and software supply chain were not compromised

Vercel stated it found no evidence that npm packages published by the company were affected by the breach and said its software supply chain remains safe. The statement narrowed the apparent impact of the incident beyond previously disclosed internal-system access.

AI-pwned: Vercel breach traced to stolen employee creds • The Register
Apr 23, 202625d ago

Vercel says expanded probe found more compromised customer accounts

Vercel disclosed that its ongoing investigation found an additional set of customer accounts compromised after attackers accessed internal systems in the Context.ai-linked breach. The company also identified a small number of separate customer-account compromises that predated and were independent of the main incident, possibly involving social engineering or malware.

Vercel Finds More Compromised Accounts in Context.ai-Linked Breach

Vercel says attackers accessed unencrypted customer credentials

Vercel said attackers reached internal systems that stored unencrypted customer credentials during the broader intrusion investigation. The disclosure marked a significant impact escalation beyond previously reported customer-account compromises and internal-system access.

Vercel says some of its customers' data was stolen prior to its recent hack | TechCrunch

Vercel says attackers stole and decrypted customer environment variables

Vercel disclosed that attackers traversed internal systems and stole and decrypted customer data, including stored environment variables, creating downstream risk to affected customers' production environments. The company said this finding came from continued analysis of nearly a petabyte of logs during its ongoing investigation.

Vercel attack fallout expands to more customers and third-party systems | CyberScoop
SOURCE COVERAGE

Sources

32 references tracked. Mallory keeps watching after this page renders.

32 SOURCESView all
Thor Collective DispatchNews
Apr 28, 2026

Hunting the Infostealer-to-SaaS Pipeline: When Third-Party Trust Becomes Lateral Movement

dispatch.thorcollective.com

Open source
ScworldNews
Apr 24, 2026

Further Vercel customer data compromise confirmed | brief | SC Media

scworld.com

Open source
Vercel KbNews
Apr 24, 2026

Vercel April 2026 security incident | Vercel Knowledge Base

vercel.com

Open source
CyberscoopNews
Apr 23, 2026

Vercel attack fallout expands to more customers and third-party systems | CyberScoop

cyberscoop.com

Open source
UnclassifiedNews
Apr 23, 2026

Security Is Optional: How to Respond to a Security Breach

inc.com

Open source
Cyber Security NewsNews
Apr 23, 2026

Vercel Confirms Security Breach - Set of Customer Account Compromised

cybersecuritynews.com

Open source
The Hacker NewsNews
Apr 23, 2026

Vercel Finds More Compromised Accounts in Context.ai-Linked Breach

thehackernews.com

Open source
Techcrunch Com SecurityNews
Apr 23, 2026

Vercel says some of its customers' data was stolen prior to its recent hack | TechCrunch

techcrunch.com

Open source
VulnuNews
Apr 22, 2026

Vercel Says Some of its Customers’ Data Was Stolen Prior to Recent Hack

vulnu.com

Open source
ItproNews
Apr 21, 2026

Everything we know about the Vercel data breach so far | IT Pro

itpro.com

Open source
Register SecurityNews
Apr 21, 2026

AI-pwned: Vercel breach traced to stolen employee creds • The Register

go.theregister.com

Open source
Data Breaches NetNews
Apr 21, 2026

Vercel Confirms Cyber Incident After Sophisticated Attacker Exploits Third‑Party Tool - DataBreaches.Net

databreaches.net

Open source
Specterops BlogNews
Apr 21, 2026

Vercel Breach Analysis: How an OAuth Token Became an Identity Attack Path | SpecterOps

specterops.io

Open source
The Record MediaNews
Apr 21, 2026

Cloud platform Vercel says company breached through third-party AI tool | The Record from Recorded Future News

therecord.media

Open source
Expel BlogNews
Apr 20, 2026

OAuth hijacked: How a third-party breach hit Vercel | Expel

expel.com

Open source
CyberscoopNews
Apr 20, 2026

Vercel's security breach started with malware disguised as Roblox cheats | CyberScoop

cyberscoop.com

Open source
Techrepublic Com SecurityNews
Apr 20, 2026

Vercel Confirms Major Security Incident as Hacker Claims $2M Ransom Demand

techrepublic.com

Open source
Toms HardwareNews
Apr 20, 2026

AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace - hacker seeking $2 million for stolen data | Tom's Hardware

tomshardware.com

Open source
UnclassifiedNews
Apr 20, 2026

Vercel Breached via Context AI Supply Chain Attack

ox.security

Open source
Security AffairsNews
Apr 20, 2026

Third-party AI hack triggers Vercel breach, internal environments accessed - Security Affairs

securityaffairs.com

Open source
The Hacker NewsNews
Apr 20, 2026

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

thehackernews.com

Open source
Cyber Security NewsNews
Apr 20, 2026

Vercel Confirms Data Breach - Hackers Claim Access to Internal Systems

cybersecuritynews.com

Open source
Register SecurityNews
Apr 20, 2026

Next.js developer Vercel warns customer creds compromised • The Register

go.theregister.com

Open source
Techcrunch Com SecurityNews
Apr 20, 2026

App host Vercel says it was hacked and customer data stolen | TechCrunch

techcrunch.com

Open source
CyberthroneNews
Apr 20, 2026

Vercel Confirms Security Breach - TheCyberThrone

thecyberthrone.in

Open source
Help Net SecurityNews
Apr 20, 2026

Vercel breached via compromised third-party AI tool - Help Net Security

helpnetsecurity.com

Open source
Bank Info SecurityNews
Apr 20, 2026

Vercel Traces Customer Data Theft to Agentic AI Tool Breach

bankinfosecurity.com

Open source
GovinfosecurityNews
Apr 20, 2026

Vercel Traces Customer Data Theft to Agentic AI Tool Breach

govinfosecurity.com

Open source
Dark ReadingNews
Apr 20, 2026

Vercel Employee's AI Tool Access Led to Data Breach

darkreading.com

Open source
Register SecurityNews
Apr 20, 2026

Next.js developer Vercel warns customer creds compromised • The Register

theregister.com

Open source
Hackernews BreachNews
Apr 19, 2026

Vercel April 2026 security incident | Hacker News

news.ycombinator.com

Open source
Bleeping ComputerNews
Apr 19, 2026

Vercel confirms breach as hackers claim to be selling stolen data

bleepingcomputer.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.