Vercel Platform Abused for Phishing Campaigns | MSSP Advisory
High
DateMay 7, 2026
📋Executive Summary
Attackers are exploiting Vercel's serverless hosting platform to launch phishing campaigns, taking advantage of its legitimate *.vercel.app domains to bypass email security filters. The campaigns target credential harvesting by hosting convincing phishing pages that inherit Vercel's reputation and SSL certificates. Cofense reports this represents a significant uptick in abuse of the platform's free hosting tier.
⚠️Why It Matters for MSSPs
Your email security stack likely trusts Vercel domains by default, creating a blind spot that attackers are now exploiting at scale. Clients expect you to catch phishing before it hits their users, but these campaigns slip through because security tools see legitimate infrastructure hosting malicious content.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.