Command Palette
Search for a command to run...

Vercel says its breach began with a compromised Google Workspace OAuth app

techcybersecurity 28 posts · 16 accounts

Vercel said the incident came from a compromised Google Workspace OAuth app tied to a third-party AI tool and published an IOC for admins to check.

From the sources (25 posts)

@intcyberdigest

🚨 BREAKING: Vercel has been breached. A threat actor has listed their customers' data, source code, databases, and keys up for sale. Vercel has also publicly disclosed they've identified a security incident involving unauthorized access to

@degeneratenews

NEW: @vercel SAYS IT HAS "IDENTIFIED A SECURITY INCIDENT THAT INVOLVED UNAUTHORIZED ACCESS TO CERTAIN INTERNAL VERCEL SYSTEMS" - "WE HAVE IDENTIFIED A LIMITED SUBSET OF CUSTOMERS THAT WERE IMPACTED" SOURCE: https://

@darkwebinformer

‼️ Vercel has allegedly been breached by ShinyHunters, with a ransom demand of $2,000,000.

@darkwebinformer

RT @DarkWebInformer: ‼️ Vercel has allegedly been breached by ShinyHunters, with a ransom demand of $2,000,000. h…

@yuchenj_uw

> Vercel got pawned > severe enough to notify law enforcement > the only advice: “review your environment variables” > what does that even mean? > $10B company, and this is how you communicate Cyber attacks ramping fast, sta

@hesamation

VERCEL GOT BREACHED. so I guess this is the modern internet huh? breach after breach after supply chain attack.

@darkwebinformer

ShinyHunters is claiming they are not behind this breach. I guess only time will tell if Vercel ends up on their DLS. 🤷‍♀️

@intcyberdigest

🚨 We've obtained alleged chat logs between Vercel and the threat actor who is LARPing as ShinyHunters and extorting them. We also spoke to the 'real' ShinyHunters, who confirmed to us they're fake. Vercel told them they don’t want to pay

@hackingdave

RT @T3chFalcon: Vercel was breached. Here’s what you need to know. TLDR: The hacker group ShinyHunters says they are selling Vercel’s sou…

@certikalert

#CertiKInsight 🚨 @vercel is reporting a security incident. Stay vigilant!

@certik

RT @CertiKAlert: #CertiKInsight 🚨 @vercel is reporting a security incident. Stay vigilant!

@techmeme

Vercel says it detected unauthorized access to its internal systems after a hacker using the ShinyHunters handle claimed a breach on BreachForums (@lawrenceabrams / BleepingComputer) (Visit Techmeme dot com for the link and full context!)

@intcyberdigest

Update from Vercel (they didn’t defang so did that for you): Our investigation has revealed that the incident originated from a third-party AI tool whose Google Workspace OAuth app was the subject of a broader compromise, potentially affe

@darkwebinformer

‼️ Vercel has provided the following update on their blog. IOC: OAuth App: 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj[.apps[.googleusercontent[.com

@suppvalen

RT @k1rallik: VERCEL GOT HACKED ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on…

@darkwebinformer

RT @DarkWebInformer: ‼️ Vercel has provided the following update on their blog. IOC: OAuth App: 110671459871-30f…

@mattjay

Seems to be the source is an integrated AI app

@officer_secret

Vercel has been hacked! According to @acceleratooooor , here's how to triage: 1. Go to 2. Security → Access and data control → API controls → App access control → Manage Third-Party App Access 3. Search for clien

@officer_secret

A friendly reminder that even NON VERCEL USERS are at risk: > next.js is owned by vercel > "npx skills add" is vercel > as well an entire ecosystem of frontend and AI backbone packages Someone on BreachForums claims to have vercel internal

@theo

@jaimeblascob My sources agree with this analysis

@theo

RT @jaimeblascob: Google has deleted the account but I’m confident the third party AI tool that vercel mentioned in the blog post is contex…

@theo

Fwiw, I am impressed with how Vercel has handled this incident so far. They’re taking it seriously. Notifying affected parties within minutes of identification. Being realistic about what they do and don’t know. They’re clearly more worri

@theo

There’s also a bunch of third parties they could throw under the bus but they are fully focused on fixing the issues instead. Incidents like this are never easy. We’re going to start seeing more and more of them as LLMs get more powerful.

@theblockco

Web3 hosting backbone Vercel confirms breach as supposed hacker demands $2 million ransom

@theo

RT @rauchg: Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situa…

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive