Zeabur is facing renewed scrutiny after a dark web forum post claimed the seller had obtained the company’s full database and was offering it for sale. The claim spread in a cybersecurity community on Threads earlier on Aug. 29.
The post said the material included source code, databases, AWS administrative keys, control of Google Cloud Platform projects, and Google Workspace administrator credentials. It also claimed the compressed package totaled 612GB.
Listing included cluster access, VPN channels, and Stripe API keys
The seller’s list also mentioned Kubernetes cluster administrator access, usable VPN channels, and Stripe API keys, and included a Telegram contact for buyers. At this stage, those details remain one-sided claims and have not been verified by a third party.
Co-founder says current evidence points to exported environment variables
Zeabur co-founder Lin Yuan-Lin responded in a post on the morning of Aug. 29. He said the attacker used a leaked AWS administrative key to enter an AWS shared cluster located in a Tokyo data center, gained access to the control-plane VPN, and then reached the primary database.
Lin said log analysis only showed targeted queries and exports of environment variables. The attacker appeared to focus on credentials such as AI API keys rather than extracting customer data in bulk. Based on the evidence currently available, he said, the company cannot substantiate the dark web seller’s claim of having the full database.
Compensation review aims for payout by Sept. 30
On compensation, Lin said cases will be reviewed one by one based on support ticket records, with payouts targeted for completion by Sept. 30 at the latest. Larger claims or special cases may take more time.
He also said credit card information is stored within Stripe’s system and cannot be accessed or used even by internal Zeabur staff, which means card fraud should not result from this incident.
Users told to rotate credentials and check server access
For services deployed on Zeabur, the company said access may have occurred, but added that it has found no direct evidence showing any data other than environment variables was accessed.
Zeabur said the main risk lies in cases where users placed directly usable database credentials in environment variables and where those databases were reachable from the public internet. In that scenario, an attacker could try to log in with scripts. That is why the company is asking users to rotate credentials across the board.
The steps Zeabur urged users to take now are specific:
- revoke all credentials and keys stored in Zeabur environment variables immediately;
- watch third-party services, especially AI APIs, for abnormal usage and billing activity;
- replace SSH passwords and keys on managed servers;
- review SSH login records for unfamiliar accounts;
- restrict access sources to specific IP addresses.
Whether the dark web listing reflects a real data package or an exaggerated sales pitch remains unresolved for now, pending a report from a third-party security firm.

