{"id":236428,"date":"2026-04-23T14:43:42","date_gmt":"2026-04-23T14:43:42","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/23\/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack-techcrunch\/"},"modified":"2026-04-23T14:43:42","modified_gmt":"2026-04-23T14:43:42","slug":"vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/23\/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack-techcrunch\/","title":{"rendered":"Vercel says some of its customers&#8217; data was stolen prior to its recent hack | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">App and website hosting giant Vercel on Thursday said hackers had accessed some of its customers\u2019 data before the company discovered <a href=\"https:\/\/techcrunch.com\/2026\/04\/20\/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai\/\" target=\"_blank\" rel=\"noopener\">its recent data breach<\/a>, suggesting that this incident may have broader security implications than initially known.<\/p>\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/vercel.com\/kb\/bulletin\/vercel-april-2026-security-incident\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">an update on its security incident page<\/a>, Vercel said it had identified evidence of malicious activity on its network preceding the early-April breach after it expanded its initial investigation.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods,\u201d the update reads.<\/p>\n<p class=\"wp-block-paragraph\">Vercel also said it discovered more customer accounts compromised by the April incident, but did not disclose details, only saying that it had notified customers known to be affected so far.<\/p>\n<p class=\"wp-block-paragraph\">The San Francisco-based app and website hosting company initially said its internal systems were breached after an employee downloaded an app made by software startup Context AI, which hackers abused to gain access to the employee\u2019s work account and, subsequently, Vercel\u2019s systems.<\/p>\n<p class=\"wp-block-paragraph\">The new update suggests the data breach may be larger in scope and could have lasted longer than initially thought.<\/p>\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/x.com\/rauchg\/status\/2047150411170320808\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a post on X<\/a>, Vercel CEO Guillermo Rauch confirmed that the hackers who compromised Vercel have been active \u201cbeyond that startup\u2019s compromise,\u201d referring to Context AI, which <a href=\"https:\/\/context.ai\/security-update\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed an earlier breach of its systems<\/a> in a post this week.<\/p>\n<p class=\"wp-block-paragraph\">A Vercel spokesperson declined to comment beyond the update on the incident page. They would neither confirm how many customers the breach now affects, nor say how far the second compromise dates back.<\/p>\n<p class=\"wp-block-paragraph\">Vercel has not yet confirmed how the hackers broke into its systems, but Rauch pointed to early signs that the hackers relied on malware that compromises computers \u201cin search of valuable tokens like keys to Vercel accounts and other providers.\u201d <\/p>\n<p class=\"wp-block-paragraph\">Rauch may be referring to information stealing malware, or infostealers, which often masquerade as legitimate software. When installed, the malware collects and uploads sensitive secrets from the victim\u2019s computer, including passwords and other private keys, allowing hackers to enter any system that those keys allow access to.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOnce the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables,\u201d said Rauch.<\/p>\n<p class=\"wp-block-paragraph\">The hackers used the hijacked Vercel employee\u2019s account to gain access to some of the company\u2019s internal systems, including customer credentials that were not encrypted.<\/p>\n<p class=\"wp-block-paragraph\">Rauch\u2019s comments appear to add weight to earlier <a href=\"https:\/\/www.infostealers.com\/article\/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reporting by security researchers<\/a> that a Context AI employee\u2019s computer was infected with infostealer malware after they allegedly looked up Roblox game cheats. TechCrunch <a href=\"https:\/\/techcrunch.com\/2026\/04\/23\/another-customer-of-troubled-startup-delve-suffered-a-big-security-incident\/\" target=\"_blank\" rel=\"noopener\">reported on Thursday<\/a> that embattled compliance startup Delve, accused of faking customer data, performed the security certifications for Context AI.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not yet known how many customers are affected by the Vercel breaches and customer data thefts. Both Vercel and Context AI have suggested that the breach may affect more companies, and that more victims may come to light.\u00a0<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/04\/23\/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>App and website hosting giant Vercel on Thursday said hackers had accessed some of its customers\u2019 data before the company discovered its recent data breach, suggesting that this incident may have broader security implications than initially known. In an update on its security incident page, Vercel said it had identified evidence of malicious activity on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":236429,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-236428","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/236428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=236428"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/236428\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/236429"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=236428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=236428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=236428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}