Security3 views

Vercel Security Breach: Hackers Demand $2 Million Ransom

Vercel has confirmed a security incident following the compromise of an employee's Google Workspace account. The attacker gained access to a limited subset of customer environment variables not marked as "sensitive."

Current Situation

The threat actor, claiming to be part of the ShinyHunters group, is reportedly demanding a $2 million ransom. They claim to have stolen API keys, source code, and database information, though Vercel has not officially confirmed the full extent of the data theft.

Security Recommendations

  • Review all environment variables in your Vercel projects.
  • Immediately rotate all credentials and API keys.
  • Monitor logs for any unauthorized access or unusual activity.

According to reports from BleepingComputer, Vercel is currently investigating the scope of the exposure to ensure platform security.