Vercel says some of its customers’ data was stolen prior to its recent hack

Vercel disclosed that customer data was compromised through multiple attack vectors prior to and beyond its initial April breach, including evidence of social engineering and infostealer malware targeting employee credentials and API keys, significantly expanding the scope and timeline of the security incident. This breach highlights critical vulnerabilities in supply chain security, credential management practices, and the effectiveness of endpoint protection, requiring IT leaders to reassess their incident response protocols and implement stronger controls around sensitive tokens and environment variables. The involvement of multiple compromised systems (Vercel, Context AI, and potentially others) demonstrates how a single malware infection can cascade into enterprise-wide breaches, affecting customers downstream and creating broader ecosystem risk.

TechCrunch2 min read
Read full article
Vercel says some of its customers’ data was stolen prior to its recent hack
The app and website hosting company has found evidence of a second compromise of customer accounts after expanding its initial investigation following a breach in early April.