logo

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

ID: 79a25cfc-7e5b-5bbd-9e90-f2019ebc1ab0

STIX ID: report--79a25cfc-7e5b-5bbd-9e90-f2019ebc1ab0

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Vercel disclosed a supply-chain-related breach stemming from a compromised Context.ai employee account, which the attacker used to take over the employee's Vercel Google Workspace access and retrieve certain non-sensitive environment variables and customer credentials; a subset of customers had credentials compromised and ShinyHunters claimed to be selling the stolen data. Hudson Rock reported the Context.ai employee was infected with Lumma Stealer, suggesting the initial compromise led to escalation; Vercel is working with Mandiant and others, advising admins to check a specific OAuth application and rotate credentials as needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.