Someone on BreachForums claiming to be ShinyHunters is selling what they say is Vercel's internal database, access keys, and source code for $2M. ShinyHunters is a black-hat hacker group known for a significant number of breaches and a "pay or leak" model. Vercel has confirmed a security incident. Here's the breakdown:
> The listing claims to include employee accounts with access to internal deployments, API keys, NPM tokens, and GitHub tokens, with a $500k BTC starting price
> ShinyHunters posted the listing on April 19, 2026, claiming verified access keys "for a potential global supply chain attack"
> The listing includes screenshots from what appears to be Vercel's internal Linear instance and an internal user member system showing fields like id, name, email, admin status, and timestamps
> The seller explicitly pitched the supply chain angle, noting Vercel owns Next.js, Turbo.js, and the broader ecosystem, with 6 million weekly downloads for Next.js alone
> Screenshots show Vercel reached out to ShinyHunters on Telegram asking them to stop contacting employees, confirming Vercel is aware and engaged
> Vercel's official statement confirms "unauthorized access to certain internal Vercel systems" and says they've engaged incident response experts and notified law enforcement
> Vercel says a "limited subset of customers" were impacted and they're reaching out directly
> Vercel is recommending all customers review environment variables and enable the sensitive environment variable feature
Vercel has reportedly been breached by ShinyHunters. As of now, nobody else appears to be posting about this, so I’m sharing what I have. Here is the information I’ve gathered, along with screenshots provided by ShinyHunters.
#cybernews #shinyhunters #breach #vercel #news