INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Context AI Hack Exposes Limited Customer Credentials at Vercel

| 2026-04-20 03:35 HIGH HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
On April 20, 2026, a security breach was disclosed by Vercel, allowing unauthorized access to "certain" internal systems. A threat actor using the ShinyHunters persona claimed responsibility for the hack and sold stolen data for $2 million. The attack is believed to have originated from the compromise of [IOC HIDDEN • LOGIN REQUIRED] in February 2026, where a Lumma Stealer malware was used to harvest corporate credentials including Google Workspace credentials, Supabase keys, Datadog logins, Authkit keys, and the "[IOC HIDDEN • LOGIN REQUIRED]" account. A limited subset of Vercel customers had their credentials compromised, with approximately 110 customers affected. The attack works by exploiting vulnerabilities in third-party tools like [IOC HIDDEN • LOGIN REQUIRED] to gain access to internal systems, which were then used to escalate privileges within Vercel's infrastructure.
Technical Mitigations AI-generated
• Block or hunt for the OAuth application <a href="/auth/login?next=/detail/PzFjqp0BE2dljnfgHmPP" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> • Use a secure and up-to-date version of Lumma Stealer detection techniques to identify potential infections on <a href="/auth/login?next=/detail/PzFjqp0BE2dljnfgHmPP" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> employee accounts • Monitor for suspicious activity related to the ShinyHunters persona, including game exploits and Roblox 'auto-farm' scripts
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

su•••@co•••.•••
co•••••.ai
11•••••.com
Ne•••••.js
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lumma StealerLumma Stealer
Target & Sectors
Global Scope
Intelligence Sources