Important disclaimer
This is an independent, community-built tool — it is not affiliated with Zeabur, and nothing it generates is legal advice. It only helps you organize the facts and evidence into a clear claim; whether you're reimbursed, and how much, is entirely up to Zeabur's own review. Please double-check every detail before you send it.
Which channel should you use to file a claim?
After this incident, you can report your loss and request compensation through the channels below. Use the official support ticket as your primary channel — treat email as a backup only.
Incident summary
On August 27, 2026, Zeabur notified affected users that, beyond the previously disclosed scope, attackers also retrieved project environment variables matching sensitive credential naming patterns or value formats.
Environment variables that may have been exposed include (but are not limited to):
- ANTHROPIC_API_KEY
- OPENROUTER_API_KEY
- OPENAI_API_KEY
- DATABASE_URL
- GITHUB_TOKEN
- JWT_SECRET
- MONGODB_URI
- MYSQL_PASSWORD
- POSTGRES_PASSWORD
- REDIS_PASSWORD
- SECRET_KEY
- and any variable whose value matches a confirmed AWS, GitHub, Anthropic, OpenRouter, OpenAI, or Stripe credential format, regardless of variable name
Zeabur states it has found no evidence that Zeabur account credentials, personal data, server logs, other project data, or payment/card information were retrieved.
Recommended: Zeabur’s official support ticket
Zeabur's incident notification explicitly stated that related tickets would be handled with the highest priority, and the ticket portal has a dedicated "Billing" category — making it the most direct and formal channel for a financial claim like this one.
Go to Zeabur SupportWhen creating the ticket, choose the "Billing" category so it reaches the right team immediately.
Backup: Email (not an officially designated claims channel)
Based on publicly available Terms of Service content, Zeabur has no dedicated email address for security or compensation claims, so email is not a formal claims channel. Use this text only as a personal paper trail, or as a follow-up if your ticket goes unanswered for a long time — not as a replacement for filing a ticket.
Before you send it, a few things worth knowing from the Terms of Service
The following is a summary based on publicly available information — refer to Zeabur's official Terms of Service page for the authoritative text.
- Zeabur's total liability under its Terms is capped at whichever is greater: US$100, or the fees you paid Zeabur in the 12 months before the incident. That is a platform-fee-level contractual cap — it does not guarantee full reimbursement of third-party charges from providers like Anthropic or OpenAI.
- The Terms expect users to report unauthorized account or security use to Zeabur promptly.
- The Terms don't define a fixed compensation formula for security incidents. This claim is a discretionary, evidence-backed request, not a guaranteed contractual entitlement.
- Disputes under the Terms are resolved through binding individual arbitration (no class actions) — worth knowing as last-resort background, not something you need to act on for this claim.
Fill in your claim details
Fill in the fields below as accurately as you can; the tool will assemble them into a complete ticket or email. Any field you leave blank will show up as a bracketed placeholder in the generated text so you can fill it in later.