An attacker moved through third-party systems to steal credentials and sensitive data from Vercel after compromising a Context.ai employee’s machine with Lumma Stealer. Vercel and Context.ai say a limited number of customers were affected, investigators including CrowdStrike and Mandiant are involved, and a group claiming to be ShinyHunters is attempting to sell the stolen data. #LummaStealer #ShinyHunters
Keypoints
- The breach began when a Context.ai employee’s device was infected with Lumma Stealer after searching for Roblox exploits.
- Attackers used stolen OAuth tokens to take over a Vercel employee’s Google Workspace account and access environment variables.
- Vercel says a limited number of customers were impacted and advised affected customers to rotate credentials and review logs.
- A group claiming to be ShinyHunters is attempting to sell stolen access keys, source code, and databases.
- Context.ai and Vercel investigations, aided by CrowdStrike and Mandiant, are ongoing amid concerns about overly privileged SaaS integrations.
Read More: https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/