📰 Full Story
Vercel, the cloud platform behind Next.js and widely used for deploying web apps, disclosed a security incident on April 18–19, 2026 after attackers gained unauthorized access to certain internal systems.
The company said a compromised third‑party AI tool and an associated Google Workspace OAuth app were the vector for the intrusion; Vercel published an indicator of compromise (OAuth app client ID) and urged administrators to audit for its use.
Vercel engaged incident responders (including Mandiant), notified law enforcement and said its services remain operational.
The company reported a limited subset of customers was affected and that environment variables explicitly marked “sensitive” show no evidence of being read, but non‑sensitive variables containing secrets should be treated as potentially exposed and rotated.
A threat actor claiming to be ShinyHunters posted purported employee records (about 580 entries) and offered data and access for sale, reportedly seeking $2 million; Vercel has not confirmed ransom negotiations.
Investigation and customer notifications are ongoing.








💬 Commentary