logo

Vercel Confirms Security Breach After Customer Accounts Were Compromised

ID: 10eeee4c-eb99-5414-9427-e69ec7d7ba9a

STIX ID: report--10eeee4c-eb99-5414-9427-e69ec7d7ba9a

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: AnuPriya

...
...

Vercel disclosed an active breach originating from a compromised Context.ai OAuth app that allowed attackers to assume an employee Google Workspace identity, access an employee Vercel account, and enumerate/decrypt non‑sensitive environment variables for a limited subset of customers (potentially exposing API keys, tokens, and credentials). The company published the OAuth client ID for hunting, is collaborating with external responders and law enforcement, has notified impacted customers to rotate secrets and enable stronger protections, and continues to investigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.