Back to overview
Resolved

Unauthorized Access to Project Environment Variable Data

Aug 28, 2026 at 7:11am UTC
Affected services
Dashboard (zeabur.com/projects)

Resolved
Sep 4, 2026 at 6:29pm UTC

Security Incident Investigation Update

We have now completed our internal investigation into the recent Zeabur security incident and have confirmed that the affected systems are currently secure.

Since the incident was contained, we have not observed any further suspicious activity related to this event. We have fully blocked the confirmed intrusion path and completed a comprehensive rotation of relevant internal credentials and passwords.

Although the investigation has concluded, we will continue to maintain enhanced monitoring and further strengthen our security controls, access restrictions, audit logging, and internal security mechanisms.

We are currently working with an independent third-party security firm to review and validate the final incident report. We expect to publish a public version of the report on Monday, September 7.

The report will provide a detailed explanation of the root cause, attack path, confirmed impact, and the remediation and security improvements implemented following the incident.

Compensation requests for losses caused by unauthorized use of exposed AI API keys remain open.

If your OpenAI, Anthropic, Gemini, OpenRouter, or other AI API key was misused as a result of this incident, please submit a support request at zeabur.com/support and include screenshots from the relevant provider dashboard.

Where possible, please provide daily and per-key usage statistics that clearly show the abnormal usage, affected time period, and associated charges. This will help us verify the claim and proceed with compensation as quickly as possible.

We sincerely apologize again for the impact caused by this incident and appreciate your patience throughout the investigation and remediation process.

Updated
Sep 3, 2026 at 2:00pm UTC

September 3 Update on the Zeabur Security Incident

Dear Zeabur users,

Zeabur is currently working with an independent third-party institution to conduct a security audit. We are also carrying out a series of system improvements and infrastructure upgrades across the platform.

During the upgrades, certain Backend and Dashboard features became temporarily unavailable. We sincerely apologize to everyone affected and for the inconvenience caused.

Regarding the recent security incident, we have progressively implemented remediation measures and addressed the related service disruptions identified to date. We will continue to strengthen Zeabur’s infrastructure, security controls, and operational processes in the coming period, with the goal of further improving the platform’s overall security, stability, and reliability. As this work continues, we will take additional care to validate changes and minimize any impact on existing services.

We would also like to express our sincere appreciation to everyone who reported issues through Discord and Support tickets. Your reports and the information provided have greatly helped us assess the scope and impact of the security incident, investigate its causes, and carry out our incident response and remediation work more efficiently.

If you encounter any further issues with the Backend, Dashboard, or other platform functionality during this period, please let us know by submitting a Support ticket. We appreciate your effort and will investigate and address any issues as promptly as possible.

Once again, we sincerely apologize for the inconvenience caused by the recent security incident and related service disruptions. We are deeply grateful for your patience, understanding, and continued support.

Zeabur Team

Updated
Aug 31, 2026 at 9:00pm UTC

August 31 Update on the Zeabur Security Incident

We would like to share the latest progress regarding the recent Zeabur security incident.

1. Service disruptions caused by security hardening work

As of today, following the initial containment and remediation actions, we have not observed any further suspicious activity or additional intrusion attempts related to this incident.

Our team is continuing to strengthen the security of our systems. During this work yesterday, changes to internal access controls and security policies unintentionally disrupted several product functions, including GitHub-related features, environment variable management, and email-related functionality.

All affected services have since been restored.

We would like to clarify that these disruptions were caused by our internal security hardening work and were not the result of a new external intrusion or security incident.

2. Compensation requests are continuing to be processed

We have now substantially completed the initial review of compensation requests submitted within the first 72 hours after the incident.

The team is currently consolidating the verified cases and preparing the next steps for compensation execution.

For some requests, the submitted evidence is not yet sufficient for us to confirm the reported unauthorized usage. In these cases, we have requested additional information through the corresponding support tickets.

If you have submitted a compensation request but have not yet received confirmation, please continue to monitor your support ticket for follow-up requests or updates.

3. Final incident report is in progress

We have completed the initial draft of our incident investigation report.

To ensure that the final report provides a complete and accurate account of the attack path, root causes, impact, and the measures we are taking to prevent similar incidents in the future, we are continuing to investigate and verify several remaining details.

We will publish the full report once these details have been sufficiently validated.

If you still require assistance related to this incident, please submit a support request at zeabur.com/support.

We sincerely apologize again for the impact and losses caused by this incident.

Our team will continue working through the remaining compensation, investigation, and security improvement efforts until the incident has been fully and properly addressed.

Updated
Aug 30, 2026 at 9:07pm UTC

Latest Update on the Zeabur Security Incident

We would like to share the latest updates and additional clarification regarding the recent Zeabur security incident.

1. Compensation requests are being reviewed and processed

We have received a significant number of reports and supporting evidence from affected customers regarding unauthorized usage.

At this time, approximately 63% of submitted compensation requests have been verified and are moving into the compensation processing stage. Around 21% are still under review, while a smaller number of cases require additional supporting evidence from the customer before verification can be completed.

Due to the current volume of requests, response times may be slower than usual. We are making every effort to respond to each related support ticket within 12–24 hours.

We appreciate your patience while we work through these cases.

2. Please be cautious of unverified external information and suspicious links

During our investigation, we have identified posts and messages circulating on some online forums and chat groups that contain unverified claims, including information that conflicts with the evidence currently available to our internal investigation.

Some of these materials appear to reuse publicly disclosed information about this incident in ways that may be misleading or potentially fraudulent.

We strongly recommend that users avoid clicking suspicious links related to this incident and do not submit payment information, credit card details, credentials, or other sensitive information on untrusted websites.

Unless we obtain sufficient evidence to independently verify such external claims, we will not respond to each unverified report individually. We recommend referring to Zeabur’s official incident updates for confirmed information.

3. Current system status

As stated in our previous update, the incident was contained on the day it was discovered.

We have since completed the rotation of relevant credentials and passwords, and have substantially expanded our internal audit logging and monitoring coverage.

As of this update, we have observed no suspicious activity related to this incident over the past 72 hours.

Enhanced monitoring remains in place across our systems.

4. Additional clarification on the attack path and Zeabur core systems

We would also like to clarify one aspect of the attack path described in our previous update.

We have confirmed that the attacker used a leaked high-privilege AWS credential to gain access to a Zeabur shared cluster hosted on AWS. This cluster was part of an edge service that was already in the process of being phased out.

However, Zeabur’s core backend services are not hosted on AWS. They run in a separate environment with another cloud provider and are protected by device-level VPN access restrictions.

Based on the attack path reconstructed so far, after gaining access to the shared cluster, the attacker obtained the internal connectivity that the cluster used to access the core system database, which ultimately allowed access to the primary database.

Based on the system logs, audit records, and other evidence collected to date, we have found no evidence that the attacker successfully obtained credentials from the shared cluster that could be used to access other core backend services.

We have also found no evidence that the attacker accessed, controlled, or attempted to compromise any Zeabur core backend services other than the primary database.

Our team is continuing the full incident reconstruction and forensic investigation. If new evidence emerges that materially changes these findings, we will publish an update promptly.

A full incident report is still being prepared and will be published once the technical details and timeline have been fully verified.

Updated
Aug 29, 2026 at 9:17pm UTC

Incident Investigation Update

Before publishing our full investigation report, we would like to share the facts we have confirmed so far, our current understanding of the scope of the incident, and answers to several frequently asked questions.

The information below is based on the system logs, access records, and other evidence currently available to us. As our investigation with third-party security specialists is still ongoing, some conclusions may be updated if additional evidence becomes available.

Confirmed Attack Path

Based on our investigation so far, the attacker obtained a leaked internal AWS administrative credential belonging to Zeabur and used it to access our shared AWS cluster in the Tokyo region.

After gaining access to the cluster, the attacker was able to obtain VPN access to our control-plane network and subsequently connect to Zeabur’s primary database.

Following discovery of the incident, we immediately revoked and rotated the affected credentials and further restricted and hardened the relevant access paths.

Confirmed Data Access Activity

We are continuing to analyze the available database access records and related system logs.

So far, we have identified targeted queries and exports involving users’ environment variables (Variables). Based on the query patterns and subsequent activity, the attacker appears to have been specifically targeting AI service API keys and other directly usable credentials.

For other categories of sensitive data, including customer information, service configuration, and server configuration, the records currently available to us primarily show aggregate or exploratory operations, such as counting records or checking data sizes.

At this time, we have not found direct evidence that the attacker performed bulk reads or exports of the underlying data in these categories.

However, it is important to clarify that the absence of direct evidence does not allow us to completely rule out the possibility that other data may have been accessed. This remains part of the ongoing investigation.

Regarding the “Dark Web” Screenshot Circulating Online

We are aware of a screenshot currently circulating in the community claiming that a complete Zeabur database or a large volume of Zeabur customer data is being offered for sale on the dark web.

Based on the system records, observed attacker activity, and other evidence collected so far, we have not found evidence supporting the claim that the attacker obtained the complete Zeabur dataset described in that screenshot.

At this time, we are unable to verify the origin or authenticity of the screenshot.

We are nevertheless including this claim in our ongoing investigation and will update our findings if additional evidence becomes available.

Third-Party Security Investigation

Zeabur is working with professional third-party security specialists to conduct further forensic analysis, reconstruct the attack path, and determine the full scope of impact.

If we identify any material new information during this process, we will update the Incident Report and notify affected users as soon as possible.


Frequently Asked Questions

Q: Will Zeabur compensate users for losses caused by this incident?

Yes.

We have established an initial compensation process for losses resulting from unauthorized use of credentials exposed in this incident.

If you incurred additional charges that were not initiated by you, please submit the relevant information through a Zeabur support ticket, including usage records provided by the affected service provider, timestamps, amounts, and any other information that may help us verify the claim.

We will review each case individually and arrange compensation once the claim has been verified.

Our current plan is to complete payment arrangements for verified cases no later than September 30, 2026. The actual payment method may vary depending on the user’s location and the circumstances of the case.

Cases involving unusually large amounts, incomplete evidence, or circumstances requiring additional verification with third-party service providers may require more time to investigate and process.

Q: Could my credit card information have been exposed or used fraudulently?

Zeabur does not directly store full credit card numbers, card security codes (CVC), or equivalent payment credentials.

Credit card information is stored and processed by Stripe, and neither Zeabur’s application systems nor our internal team members have access to users’ complete card details.

Based on the attack path and data access activity identified so far, we have found no evidence that this incident involved access to complete credit card information stored by Stripe.

We therefore currently have no reason to believe that users’ credit card details were directly exposed as a result of this incident.

Q: Could the attacker have accessed data inside services I deployed on Zeabur?

Based on the level of access obtained by the attacker at the time, we cannot completely rule out the technical possibility that the attacker could have attempted to access data inside user-deployed services.

However, based on the evidence collected so far, we have not found direct evidence that the attacker performed large-scale access to or export of data stored inside users’ services.

If your environment variables contained directly usable database credentials, and the corresponding database was accessible from the public internet, it is technically possible that the attacker could have used automated tools to attempt to connect to that database after obtaining the credentials.

This is one of the reasons Zeabur immediately instructed affected users to rotate API keys, database passwords, and other credentials following discovery of the incident.

If you have not yet completed the relevant credential rotation, we strongly recommend doing so immediately.

Q: Is Zeabur currently safe to use?

Immediately after discovering the incident, we revoked and rotated the known affected credentials and related internal keys. We have also strengthened access controls, logging, and monitoring for suspicious activity across the affected systems.

As of now, we have not observed any continuing unauthorized activity related to this incident, nor have we identified any new activity matching the same attack pattern.

However, because the attacker obtained relatively deep access within our infrastructure and the full third-party forensic investigation is still ongoing, we are not currently making an absolute claim that every possible risk has been eliminated.

We will continue monitoring the environment, reviewing access permissions, and implementing additional security hardening measures as the investigation progresses.

Q: Could the attacker have accessed a server that I purchased or manage through Zeabur?

Based on the evidence confirmed so far, we have not found evidence that the attacker read or exported server connection configuration data.

However, based on the level of system access available to the attacker at the time, it was technically possible for them to query certain information related to server connectivity.

As a precaution, we recommend that users managing servers through Zeabur:

  • Rotate SSH passwords or SSH keys
  • Review recent SSH login records
  • Check for unfamiliar accounts, SSH keys, or login sources
  • Where possible, restrict SSH access by source IP and disable password-based authentication

At this time, we have not found evidence that the attacker actually logged into user-managed servers.


We are continuing to investigate this incident and will share confirmed information as transparently as possible.

A complete incident report, including the full timeline, root cause, confirmed scope of impact, remediation measures, and longer-term security improvements, will be published after our internal investigation and third-party forensic review are complete.

Updated
Aug 28, 2026 at 5:42pm UTC

During our ongoing investigation, we identified suspicious activity involving LiteLLM, which is used by the Zeabur AI Hub service. We are currently investigating whether this activity is related to the incident.

As a precautionary measure and to prevent any potential further impact, we are temporarily suspending Zeabur AI Hub services while the investigation continues.

Created
Aug 28, 2026 at 7:11am UTC

We detected unauthorized access to an internal service credential that was used to retrieve project environment variable records. We revoked the affected credential, blocked the access path, and contained the incident on the same day.

Our investigation confirmed exposure of environment variables with the following key names:

ACCESS_TOKEN, API_SECRET, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CF_API_TOKEN, CLIENT_SECRET, CLOUDFLARE_API_TOKEN, DIGITALOCEAN_TOKEN, GEMINI_API_KEY, GITHUB_PAT, GITHUB_TOKEN, GOOGLE_API_KEY, LINODE_TOKEN, PRIVATE_KEY, STRIPE_PUBLISHABLE_KEY, STRIPE_SECRET_KEY, ANTHROPIC_API_KEY, OPENROUTER_API_KEY, OPENAI_API_KEY, DATABASE_URL, JWT_SECRET, MONGODB_URI, MYSQL_PASSWORD, POSTGRES_PASSWORD, REDIS_PASSWORD, and SECRET_KEY.

We also confirmed exposure of credentials stored under custom variable names when their values matched identifiable AWS, GitHub, Anthropic, OpenRouter, OpenAI, or Stripe credential formats.

Affected users are being notified directly with the relevant projects, services, environments, and recommended rotation actions. We strongly recommend that notified users immediately revoke and replace all listed credentials and review the corresponding databases and third-party services for unusual access, usage, or charges.

At this time, we have found no evidence that Zeabur account credentials, personal information, server data, payment information, or credit card information were accessed. Our investigation remains ongoing, and we will provide further updates as they become available.