logo

Vercel Breach Linked to Context.ai, ShinyHunters Says It’s Not Involved

ID: a7598960-b1de-56c0-8e39-21e6bc7d649c

STIX ID: report--a7598960-b1de-56c0-8e39-21e6bc7d649c

Feed Name: HackRead

Threat Score
65/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Waqas

...
...

Vercel confirmed a security incident stemming from a third-party compromise at Context.ai where a Google Workspace account was abused via OAuth to access limited Vercel resources (employee information, internal logs, and some environment variables). A threat actor advertised alleged stolen data on BreachForums under the name ShinyHunters (later denied by the real group), Hudson Rock researchers suggested a possible Lumma infostealer infection on a Context.ai employee device, and Vercel has engaged incident response teams and advised credential rotation while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.