Vercel’s Data Breach Was Worse Than Initially Thought—And Customer Credentials Weren’t Encrypted

Vercel disclosed hackers stole customer data weeks before the April breach. Forensic analysis found earlier compromises. Credentials were not encrypted.

  • Vercel disclosed hackers stole customer data before the April breach disclosure.
  • Forensic analysis revealed malicious activity that predated the incident from social engineering or malware.
  • Customer credentials in internal systems were not encrypted—only access tokens were.

App hosting giant Vercel disclosed Thursday that hackers stole customer data from some accounts weeks or months before the company detected its widely reported April breach—a revelation that suggests the incident’s scope may extend far beyond what executives first acknowledged.

The San Francisco-based company said in an updated incident report that expanded forensic analysis uncovered evidence of malicious activity that “predates this incident, potentially as a result of social engineering, malware, or other methods.” The update did not specify how many customers were affected by the earlier compromises, but it confirmed that stolen data included customer names, email addresses, phone numbers, and billing information.

Critically, Vercel acknowledged that customer credentials stored in internal systems were not encrypted—a security lapse that contradicts industry best practices. The company said passwords were hashed, but the lack of encryption for other credential data leaves affected customers vulnerable to potential misuse.

What Was Exposed

The breach has expanded from an initial disclosure that focused on environment variable leaks in April to include earlier compromises that may have involved multiple attack vectors. Vercel’s update indicates the threat actor had access to customer accounts for an extended period before detection, giving them ample time to exfiltrate sensitive data.

The unencrypted credential storage is particularly concerning given Vercel’s position as a hosting provider for thousands of applications, including those of major businesses and startups. Security researchers have noted that the combination of extended dwell time and plaintext credential storage represents a worst-case scenario for breach severity.

Vercel said it has notified affected customers and implemented additional security measures, including rotating access tokens and enhancing monitoring. The company is working with external security firms to conduct a comprehensive investigation. The incident adds to growing concerns about supply chain security in the cloud hosting sector.

Leave your vote