Cloud development platform Vercel has announced a security breach that compromised its systems. The company revealed that the attack stemmed from a compromised third-party AI tool, affecting a limited number of customers. Notable clients of Vercel include OpenAI, Cursor, Pinterest, and Bose. While the breach could lead to disruptions, Vercel assures that no sensitive information was exposed to the hackers.
The perpetrators behind the attack are believed to be associated with ShinyHunters, a group previously targeting Rockstar Games, creators of GTA. The hackers claim to be selling the stolen data from the Vercel breach online.
Vercel, a cloud platform renowned for hosting and deploying web apps, is recognized for developing the popular Next.js framework, a widely used React framework. The platform caters to a diverse range of industries such as software, retail, and AI, with only a limited number of customers likely impacted by the breach.
According to Vercel’s blog post, the breach originated from a compromised third-party AI tool utilized by an employee, leading to unauthorized access to Vercel’s environment variables. These variables, which dictate app functionality, were accessed from the employee’s Google Workplace account. Vercel states that the hackers obtained non-sensitive variables.
The hackers’ claims of a potential global supply chain attack using data from Vercel have sparked concerns. While the ShinyHunters group denies the allegations, the hackers have shared Vercel employee information, including names, email addresses, account status, and activity timestamps. Reports suggest the hackers discussed a ransom demand of $2 million.
In response to the breach, Vercel has advised customers to review and rotate sensitive environment variables. Updates have been implemented on the dashboard to enhance the management of such variables. Although Vercel’s core services remain unaffected, the company is collaborating with affected customers and law enforcement. Vercel has also released an indicator of compromise (IOC) to aid in identifying potential malicious activities.
