Vercel internal database, employee accounts, and GitHub/NPM tokens allegedly breached and offered for sale on BreachForums for $2M.
Security & Exploits ·
A breach of Vercel has been reported on X, with the intrusion attributed to ShinyHunters. According to the report, internal database contents, employee account credentials, and tokens for GitHub and NPM have been compromised and are being offered for sale on BreachForums at a $2 million asking price.
The claim remains isolated to a single source at present, with no corroboration from other outlets or official confirmation from Vercel itself. The reporter notes that screenshots were provided by ShinyHunters to support the breach claim, though the full scope and verification of those materials are not detailed in the available information.
It is not yet clear whether Vercel has acknowledged the incident, what customer or project data may have been exposed through the compromised internal systems, or whether the asking price reflects actual buyer interest or represents an initial demand that may shift during negotiation.