Unauthorized Access to Project Environment Variable Data
Last updateresolvedSep 4 · 18:29 UTC
## Security Incident Investigation Update We have now completed our internal investigation into the recent Zeabur security incident and have confirmed that the affected systems are currently secure. Since the incident was contained, we have not observed any further suspicious activity related to this event. We have fully blocked the confirmed intrusion path and completed a comprehensive rotation of relevant internal credentials and passwords. Although the investigation has concluded, we will continue to maintain enhanced monitoring and further strengthen our security controls, access restrictions, audit logging, and internal security mechanisms. We are currently working with an independent third-party security firm to review and validate the final incident report. We expect to publish a public version of the report on **Monday, September 7**. The report will provide a detailed explanation of the root cause, attack path, confirmed impact, and the remediation and security improvements implemented following the incident. Compensation requests for losses caused by unauthorized use of exposed AI API keys remain open. If your OpenAI, Anthropic, Gemini, OpenRouter, or other AI API key was misused as a result of this incident, please submit a support request at **zeabur.com/support** and include screenshots from the relevant provider dashboard. Where possible, please provide daily and per-key usage statistics that clearly show the abnormal usage, affected time period, and associated charges. This will help us verify the claim and proceed with compensation as quickly as possible. We sincerely apologize again for the impact caused by this incident and appreciate your patience throughout the investigation and remediation process.
Reported by Zeabur on their status page.
