logo

AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account

ID: 2103b449-af06-565d-91dc-78fd1793b56c

STIX ID: report--2103b449-af06-565d-91dc-78fd1793b56c

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-26

Author: Carly Page

...
...

Vercel suffered an intrusion originating from a compromised employee account (likely via Lumma infostealer) that allowed attackers to hijack Google Workspace access, abuse OAuth, and harvest environment variables and credentials; stolen data — including API keys and employee details — is reported being offered for sale, and Vercel is coordinating remediation with external responders and law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.