Summary

  • Vercel confirms unauthorized internal access; it's currently investigating and notifying law enforcement.
  • ShinyHunters claims to be selling Vercel data for $2M; claims the leak includes access keys, source code, and database.
  • Even if unverified, immediately review and rotate environment variables and secrets.

Every so often, we see a company announce a breach in its systems, followed closely by a group claiming responsibility. This is sometimes accompanied by the group advertising that they have the impacted data for sale, usually for a high price. It's often very difficult to verify whether the group does or does not have what it claims to have, but the possibility that it does always looms.

Now, something similar has happened to Vercel. While we know for sure that Vercel suffered a breach, we're hearing unverified claims from a group called the ShinyHunters that it's selling the data for $2 million.

A GTA Vi screenshot
GTA VI developer Rockstar hacked again — this time for ransom

Hacking group ShinyHunters told Rockstar Games that it should "make the right decision" and not be "the next headline."

Vercel confirms an internal data breach on its website

Review your environment variables now

A SteamOS gaming PC showing the KDE Plasma desktop environment outside of the Steam app

First, let's check out what has been confirmed. Vercel has made a statement confirming that it has suffered "unauthorized access to certain internal Vercel systems" and that it has already notified law enforcement. Right now, Vercel has both identified and notified a limited number of affected customers, but as it continues to investigate, it will update the previous statement with any further developments.

As for what you can do right now, Vercel says the following:

We recommend that all of our customers follow best practices by reviewing environment variables and taking advantage of the sensitive environment variable feature. You can view all environment variables on one page.

Even if ShinyHunters' claims turn out to be false, Vercel's confirmation of a breach means it's worth taking its advice on environment variables seriously.

why Cursor is better than Antigravity
A popular Python library just became a backdoor to your entire machine

Supply chain attacks feel like they're becoming more and more common.

2

The ShinyHunters hacker group claims responsibility for the attack

They say they're selling the data for $2 million

A laptop showing code.
Source: Unsplash

Now, let's take a look at the unverified information. The notorious hacking group ShinyHunters posted, claiming they have "Access Key/Source Code/Database From Vercel Company." They also claim that this could set the stage for "the largest supply chain attack ever," as ShinyHunters believes that Vercel logs 6 million weekly downloads from Next.js alone. In theory, a hacker could poison that package and cause some serious damage.

The group says they want $2 million for the data, starting with $500,000 Bitcoin payments. Again, it's worth taking this with a pinch of salt, as there's no hard-and-fast guarantee that ShinyHunters performed the attack, let alone that they have the data to sell.

Image_Bit_by_Bit 9
VPN used to cheat in popular online VR game gave hackers access to users' internet connections

Yet another bad look for VPNs.

2