logo

Vercel breached via compromised third-party AI tool

ID: ae83287c-91e1-5f5b-a170-78ab62adeffe

STIX ID: report--ae83287c-91e1-5f5b-a170-78ab62adeffe

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Vercel suffered a security breach after a third-party AI tool's Google Workspace OAuth app (linked to Context.ai) was compromised, allowing an attacker to take over a Vercel employee account and access some internal environments and environment variables not marked as sensitive; affected customers were notified and advised to rotate credentials and review activity logs. Vercel engaged external incident responders (including Mandiant/Google) and implemented additional protections while investigating supply-chain exposure and potential wider impact; a claim of data sale appeared on BreachForums but was later disavowed by the original group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.