Vercel has confirmed a security incident following the compromise of an employee's Google Workspace account. The attacker gained access to a limited subset of customer environment variables not marked as "sensitive."
Current Situation
The threat actor, claiming to be part of the ShinyHunters group, is reportedly demanding a $2 million ransom. They claim to have stolen API keys, source code, and database information, though Vercel has not officially confirmed the full extent of the data theft.
Security Recommendations
- Review all environment variables in your Vercel projects.
- Immediately rotate all credentials and API keys.
- Monitor logs for any unauthorized access or unusual activity.
According to reports from BleepingComputer, Vercel is currently investigating the scope of the exposure to ensure platform security.


