Vercel says some of its customers’ data was stolen prior to its recent hack
In a post on X, Vercel CEO Guillermo Rauch confirmed that the hackers who compromised Vercel have been active “beyond that startup’s compromise,” referring to Context AI, which confirmed an earlier breach of its systems in a post this week. A Vercel spokesperson declined to comment beyond the update on the incident page. They would neither confirm how many customers the breach now affects, nor say how far the second compromise dates back. Vercel has not yet confirmed how the hackers broke into its systems, but Rauch pointed to early signs that the hackers relied on malware that compromises computers “in search of valuable tokens like keys to Vercel accounts and other providers. ” Rauch may be referring to information stealing malware, or infostealers, which often masquerade as legitimate software.
“Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables,” said Rauch.
It’s not yet known how many customers are affected by the Vercel breaches and customer data thefts.
Logic Quality Breakdown:
- Updated_At:
- Truth_Blocks:
- Analysis_Method: