INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Context AI Hack Exposes Limited Customer Credentials at Vercel
| 2026-04-20 03:35 AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
On April 20, 2026, a security breach was disclosed by Vercel, allowing unauthorized access to "certain" internal systems. A threat actor using the ShinyHunters persona claimed responsibility for the hack and sold stolen data for $2 million. The attack is believed to have originated from the compromise of [IOC HIDDEN • LOGIN REQUIRED] in February 2026, where a Lumma Stealer malware was used to harvest corporate credentials including Google Workspace credentials, Supabase keys, Datadog logins, Authkit keys, and the "[IOC HIDDEN • LOGIN REQUIRED]" account. A limited subset of Vercel customers had their credentials compromised, with approximately 110 customers affected. The attack works by exploiting vulnerabilities in third-party tools like [IOC HIDDEN • LOGIN REQUIRED] to gain access to internal systems, which were then used to escalate privileges within Vercel's infrastructure.
Technical Mitigations AI-generated
• Block or hunt for the OAuth application <a href="/auth/login?next=/detail/PzFjqp0BE2dljnfgHmPP" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>
• Use a secure and up-to-date version of Lumma Stealer detection techniques to identify potential infections on <a href="/auth/login?next=/detail/PzFjqp0BE2dljnfgHmPP" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> employee accounts
• Monitor for suspicious activity related to the ShinyHunters persona, including game exploits and Roblox 'auto-farm' scripts
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
su•••@co•••.•••
co•••••.ai
11•••••.com
Ne•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Intelligence Sources
The Hacker News
2026-04-20