AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace — hacker seeking $2 million for stolen data
Source
Published
TL;DR
AI GeneratedVercel, a cloud platform linked to Next.js, faced a security breach when a hacker exploited a third-party AI tool to access a Vercel employee's Google Workspace account. The breach exposed non-sensitive data, and the hacker, known as ShinyHunters, is demanding $2 million for the stolen information. Vercel is working with Mandiant, law enforcement, and affected customers to address the breach. The attacker's initial access stemmed from a compromised Context.ai tool, which had its own security issues traced back to an employee infected with malware. Vercel is advising customers to review and secure their environment variables and has introduced new security features following the incident.