Vercel breach leaks employee data via AI tool

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Vercel announced on X that a security incident occurred, impacting a limited subset of its customers.
- ShinyHunters posted employee names, email addresses, and activity timestamps online, claiming they were stolen from Vercel.
- Vercel said the breach originated from a compromised third‑party AI tool whose Google Workspace OAuth app was compromised.
- Vercel advised administrators to review activity logs for suspicious activity and rotate environment variables, API keys, and tokens.
- Vercel released indicators of compromise (IOCs) and urged Google Workspace administrators to check for usage of the compromised app.
- Vercel noted that the compromised AI tool could affect hundreds of users across many organizations.
Why it matters: Vercel’s customers must scramble to secure their environments, as exposed employee data and potentially compromised API keys could enable unauthorized access to their applications. The incident also underscores the broader security risk of third‑party AI tools that integrate via OAuth, prompting organizations to audit such integrations.




