logo

Vercel Confirms Security Breach – Set of Customer Account Compromised

ID: e56322ce-fe58-5ac8-a136-9cf99c3441f6

STIX ID: report--e56322ce-fe58-5ac8-a136-9cf99c3441f6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Guru Baran

...
...

Vercel disclosed a supply-chain OAuth compromise originating from a Lumma Stealer infection on a Context.ai employee machine that allowed attackers to harvest OAuth tokens, hijack a Vercel employee Google Workspace account, and access/decrypt non-sensitive environment variables for a subset of customers; ShinyHunters has claimed responsibility and Vercel published an OAuth App Client ID IOC while urging customers to rotate credentials, enable MFA, and mark secrets as sensitive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.