logo

Vercel Breach Analysis: How an OAuth Token Became an Identity Attack Path

ID: a9f1a232-56c7-5ea4-bf2d-33066f5cc7a1

STIX ID: report--a9f1a232-56c7-5ea4-bf2d-33066f5cc7a1

Feed Name: SpecterOps Blog

Threat Score
80/100

Date Published: 2026-04-21

Date Updated: 2026-05-01

...
...

The report analyzes Vercel’s breach in which attackers compromised a third‑party AI tool (Context.ai), exfiltrated OAuth tokens (reportedly via Lumma Stealer), used a Vercel employee’s token to access Google Workspace, and moved laterally to expose environment variables and credentials; it frames the incident as a structural identity/supply‑chain attack and urges organizations to map and eliminate identity attack paths rather than relying on IAM hygiene alone.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.