Zeabur production-database credential incident

Zeabur confirmed that attackers read production account information and project environment variables.

Last modified

Summary

  • Environment: Shared cluster and production database
  • Operational impact: AI Hub permanently discontinued
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

Zeabur confirmed that attackers read production account information and project environment variables. [2]

Impact

The variables contained API keys, database passwords and other service credentials. [2]

Zeabur later discontinued AI Hub and returned unused balances as credits, with cash refunds available on request. [1]

Timeline

  1. Intrusion

    Unauthorized access began.

    [2]
  2. Customer warnings

    Zeabur asked affected users to replace credentials.

    [2]
  3. AI Hub discontinued

    Zeabur announced permanent closure.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

A flaw in a public NextChat service enabled access; exposed platform and cloud credentials widened the compromise. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

Zeabur revoked legacy keys, rotated internal credentials and removed the shared cluster’s production access. [2]