Data Security, Breach, Supply chain

Further Vercel customer data compromise confirmed

(Adobe Stock)

TechCrunch reports that Vercel has disclosed that unencrypted customer information had been compromised prior to this month's breach that affected its internal systems.

The hackers reportedly hijacked the account of a Vercel employee who downloaded a Context AI-made app. The company said more accounts were compromised but has not commented on the number of customers affected or how the attackers have compromised its systems. However, Vercel CEO Guillermo Rauch noted early signs that attackers utilized malware for compromising computers to look for "valuable tokens like keys to Vercel accounts and other providers."

"Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables," said Rauch. Vercel's confirmation comes after a report that a computer of a Context AI employee was infected with malware after searching for Roblox game cheats. Both companies confirmed that the breach may have impacted more organizations.

You can skip this ad in 5 seconds