Zeabur dark web post claims 612GB database sale, company says evidence does not support it

Zeabur dark web post claims 612GB database sale, company says evidence does not support it

N
News Editor
2026-08-30 05:09:11
A post on a dark web forum has pushed Zeabur back into the spotlight after the seller claimed to hold the company’s full database and offered a 612GB compressed data package for sale. The listing said the material included source code, databases, AWS administrative keys, Google Cloud Platform project control, Google Workspace admin credentials, Kubernetes cluster access, VPN channels, and Stripe API keys. None of those claims has been independently verified. Zeabur co-founder Lin Yuan-Lin said the company’s current findings point to a narrower breach path. According to his statement, an exposed AWS administrative key let the attacker enter an AWS shared cluster in a Tokyo data center, obtain control-plane VPN access, and reach the main database. Log analysis, he said, only shows targeted queries and exports of environment variables, with AI API keys and similar credentials as the focus, rather than bulk customer data extraction. Lin added that compensation will be reviewed case by case through support ticket records, with payouts aimed to be completed by Sept. 30, while larger or unusual cases may take longer. Zeabur also said users should immediately rotate credentials, review abnormal usage and bills on third-party services, replace SSH passwords and keys on managed servers, inspect login records, and restrict access sources to specific IP addresses.

Zeabur is facing renewed scrutiny after a dark web forum post claimed the seller had obtained the company’s full database and was offering it for sale. The claim spread in a cybersecurity community on Threads earlier on Aug. 29.

The post said the material included source code, databases, AWS administrative keys, control of Google Cloud Platform projects, and Google Workspace administrator credentials. It also claimed the compressed package totaled 612GB.

Listing included cluster access, VPN channels, and Stripe API keys

The seller’s list also mentioned Kubernetes cluster administrator access, usable VPN channels, and Stripe API keys, and included a Telegram contact for buyers. At this stage, those details remain one-sided claims and have not been verified by a third party.

Co-founder says current evidence points to exported environment variables

Zeabur co-founder Lin Yuan-Lin responded in a post on the morning of Aug. 29. He said the attacker used a leaked AWS administrative key to enter an AWS shared cluster located in a Tokyo data center, gained access to the control-plane VPN, and then reached the primary database.

Lin said log analysis only showed targeted queries and exports of environment variables. The attacker appeared to focus on credentials such as AI API keys rather than extracting customer data in bulk. Based on the evidence currently available, he said, the company cannot substantiate the dark web seller’s claim of having the full database.

Compensation review aims for payout by Sept. 30

On compensation, Lin said cases will be reviewed one by one based on support ticket records, with payouts targeted for completion by Sept. 30 at the latest. Larger claims or special cases may take more time.

He also said credit card information is stored within Stripe’s system and cannot be accessed or used even by internal Zeabur staff, which means card fraud should not result from this incident.

Users told to rotate credentials and check server access

For services deployed on Zeabur, the company said access may have occurred, but added that it has found no direct evidence showing any data other than environment variables was accessed.

Zeabur said the main risk lies in cases where users placed directly usable database credentials in environment variables and where those databases were reachable from the public internet. In that scenario, an attacker could try to log in with scripts. That is why the company is asking users to rotate credentials across the board.

The steps Zeabur urged users to take now are specific:

  • revoke all credentials and keys stored in Zeabur environment variables immediately;
  • watch third-party services, especially AI APIs, for abnormal usage and billing activity;
  • replace SSH passwords and keys on managed servers;
  • review SSH login records for unfamiliar accounts;
  • restrict access sources to specific IP addresses.

Whether the dark web listing reflects a real data package or an exaggerated sales pitch remains unresolved for now, pending a report from a third-party security firm.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
40

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.