HeadlinesBriefing favicon HeadlinesBriefing.com

Vercel Confirms Breach After Hackers Claim to Sell Stolen Data

Hacker News •
×

Vercel, the cloud platform behind the popular Next.js React framework, has confirmed a security breach after threat actors claimed to have accessed internal systems and were attempting to sell stolen data on a hacking forum. The company stated that a limited subset of customers was affected.

The attacker, claiming association with the ShinyHunters group, posted on a forum offering access keys, source code, and database data allegedly taken from Vercel. They shared a file containing 580 employee records with names, email addresses, and activity timestamps. The threat actor also claimed a $2 million ransom demand was discussed in communications with the company.

Vercel has engaged incident response experts and notified law enforcement, stating services remain fully operational. The company recommends customers review environment variables, use sensitive variable features, and rotate any potentially compromised secrets. BleepingComputer could not independently verify the authenticity of the stolen data or the claimed breach details.