---
title: "Zeabur production-database credential incident"
description: "Zeabur production-database credential breach: verified timeline, impact and response through October 7, 2026."
incident_type: "Vulnerability exploitation"
status: "active"
last_modified: "2026-10-07"
canonical_url: "https://www.ally.security/incidents/zeabur-production-database-credential-incident-2026"
markdown_url: "https://www.ally.security/incidents/zeabur-production-database-credential-incident-2026.md"
stix_url: "https://www.ally.security/incidents/zeabur-production-database-credential-incident-2026/stix.json"
---

# Zeabur production-database credential incident

Zeabur confirmed that attackers read production account information and project environment variables.

Last modified Oct 7, 2026 · 2 sources

## Summary

- **Environment:** Shared cluster and production database
- **Operational impact:** AI Hub permanently discontinued
- **Financial impact:** No incident cost established in the reviewed evidence

## What happened

[Zeabur](https://zeabur.com/) confirmed that attackers read production account information and project environment variables. [2](#source-2)

## Impact

The variables contained API keys, database passwords and other service credentials. [2](#source-2)

Zeabur later discontinued AI Hub and returned unused balances as credits, with cash refunds available on request. [1](#source-1)

## Timeline

### August 27, 2026 — Intrusion

Unauthorized access began. [2](#source-2)

### August 28, 2026 — Customer warnings

Zeabur asked affected users to replace credentials. [2](#source-2)

### September 22, 2026 — AI Hub discontinued

Zeabur announced permanent closure. [1](#source-1)

### October 7, 2026 — Briefing updated

This briefing was last reviewed and updated on October 7, 2026.

## Threat Group & Attack Vector

A flaw in a public [NextChat](https://github.com/ChatGPTNextWeb/NextChat) service enabled access; exposed platform and cloud credentials widened the compromise. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- T1190 — [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/). [2](#source-2)

## Response

Zeabur revoked legacy keys, rotated internal credentials and removed the shared cluster’s production access. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/zeabur-production-database-credential-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### We've Shut Down AI Hub and Refunded

official · Zeabur Inc. · Sep 22, 2026

<https://zeabur.com/changelogs/aihub-shutdown>

<a id="source-2"></a>

### Zeabur August 2026 security incident

official · Zeabur Inc. · Sep 7, 2026

<https://zeabur.com/blogs/august-2026-security-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: AI Hub discontinued
2. **Affected Organization · 100% confidence · current**  
   Zeabur production-database credential breach: Zeabur Inc.
3. **Exposed Data Category · 100% confidence · current**  
   Zeabur production-database credential breach: Account credentials
4. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: The variables contained API keys, database passwords and other service credentials.
5. **Disclosed At · 100% confidence · current**  
   Zeabur production-database credential breach: 2026-08-28
6. **Exploited Vulnerability · 100% confidence · current**  
   Zeabur production-database credential breach: CVE-2026-7644
7. **Began At · 100% confidence · current**  
   Zeabur production-database credential breach: 2026-08-27
8. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: A flaw in a public NextChat service enabled access; exposed platform and cloud credentials widened the compromise.
9. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: Zeabur revoked legacy keys, rotated internal credentials and removed the shared cluster’s production access.
10. **Used Product · 100% confidence · current**  
   Zeabur production-database credential breach: NextChat
11. **Occurred At · 100% confidence · current**  
   AI Hub discontinued: 2026-09-22
12. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: Zeabur later discontinued AI Hub and returned unused balances as credits, with cash refunds available on request.
13. **Used Attack Technique · 100% confidence · current**  
   Zeabur production-database credential breach: https://attack.mitre.org/techniques/T1190/
14. **Resulted In · 100% confidence · current**  
   Zeabur production-database credential breach: Zeabur confirmed that attackers read production account information and project environment variables.

</details>
