5 Sources
[1]
AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace -- hacker seeking $2 million for stolen data
The culprit? An infostealer infection from a Roblox cheat download. Vercel, the cloud platform behind the widely used Next.js web framework, has acknowledged a security breach after an attacker compromised a third-party AI tool called Context.ai and used it to gain access to a Vercel employee's
[2]
Next.js developer Vercel warns customer creds compromised
Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise of some customer credentials, and blamed an outfit called Context.ai for the
[3]
Vercel breach exposes the OAuth gap most security teams cannot detect, scope or contain
One employee at Vercel adopted an AI tool. One employee at that AI vendor got hit with an infostealer. That combination created a walk-in path to Vercel's production environments through an OAuth grant that nobody had reviewed. Vercel, the cloud platform behind Next.js and its millions of weekly
[4]
'Highly Sophisticated,' AI-Powered Hackers Behind Vercel Breach: CEO - Decrypt
Many crypto frontends use Vercel to host their UI, with the company advising immediate credential rotation. Vercel's CEO said a "highly sophisticated," potentially AI-assisted hacking group was behind a recent security incident that exposed some customer credentials following a breach of internal
[5]
Developer tooling provider Vercel discloses breach that exposed some users' data - SiliconANGLE
Developer tooling provider Vercel discloses breach that exposed some users' data A hacker has stolen a limited amount of customer data from Vercel Inc., a major developer tooling provider. The company disclosed the incident late Sunday. Vercel, which received a $9.3 billion valuation last year,
Share
Copy Link
Vercel, the cloud platform behind Next.js, disclosed a security breach originating from Context.ai, a third-party AI tool. A Vercel employee granted the AI tool unrestricted OAuth permissions to their corporate Google Workspace account. When Context.ai was compromised through infostealer malware, attackers inherited those permissions and accessed Vercel's internal systems, exposing non-sensitive environment variables for a limited subset of customers.
Vercel, the cloud platform powering the widely used Next.js web framework, confirmed a security incident on April 19 that resulted in unauthorized access to internal systems and compromised customer credentials for a limited subset of users
1
. The Vercel breach didn't originate within the company's own infrastructure but through Context.ai, a third-party AI tool that builds agents trained on company-specific knowledge2
. At least one Vercel employee had signed up for Context.ai's AI Office Suite using their corporate account and granted it "Allow All" OAuth permissions, creating an expansive attack surface1
.
Source: SiliconANGLE
The employee grants unrestricted access decision proved catastrophic when attackers compromised Context.ai and inherited those broad permissions. This unauthorized access to Google Workspace allowed the threat actor to take over the employee's Vercel Google Workspace account and move laterally into internal systems
1
. Context.ai acknowledged in its security bulletin that "Vercel's internal OAuth configurations appear to have allowed this action to grant these broad permissions in Vercel's enterprise Google Workspace"2
. The OAuth token compromise enabled attackers to escalate privileges by accessing non-sensitive environment variables that weren't encrypted with Vercel's sensitive designation feature3
.Cybersecurity firm Hudson Rock traced the third-party AI tool compromise back to an infostealer malware infection on a Context.ai employee's machine in February 2026
1
. According to Hudson Rock's forensic analysis, the employee downloaded Roblox auto-farm scripts and game exploit executors, which delivered Lumma Stealer malware3
. The harvested credentials included Google Workspace logins, Supabase keys, Datadog tokens, Authkit credentials, and the [email protected] account3
. Context.ai detected unauthorized access to its AWS environment in March and hired CrowdStrike to investigate, but later learned the attacker had also compromised OAuth tokens for consumer users1
.
Source: Tom's Hardware
The breach exposed compromised customer credentials stored as non-sensitive environment variables, though Vercel emphasized that variables marked as "sensitive" remain encrypted at rest and were not accessed
1
. CEO Guillermo Rauch described the attacker as "highly sophisticated and, I strongly suspect, significantly accelerated by AI," noting they "moved with surprising velocity and in-depth understanding of Vercel"4
. A threat actor using the ShinyHunters name claimed responsibility and reportedly sought $2 million for the stolen data, though Google Threat Intelligence assessed the claimant as "likely an imposter"3
. Vercel has engaged Mandiant, Google's incident response firm, notified law enforcement, and contacted affected customers directly1
.Related Stories
This incident highlights escalating security risks from third-party integrations, particularly as agentic AI products link to external services. "Because many crypto frontends use Vercel to host their UI, a breach can allow attackers to implant a wallet drainer," explained Natalie Newson, CertiK senior blockchain security researcher
4
. The dwell time raises particular concern—nearly a month separated Context.ai's March detection from Vercel's Sunday disclosure, while a separate Trend Micro analysis references an intrusion potentially beginning as early as June 20243
. John Woods, CEO of Nillion, recommended companies "lock down OAuth grants, use least privilege, enforce strict controls around sensitive environment variables, separate frontend deployment from secret or signing authority, and monitor deployments and logs closely"4
.
Source: VentureBeat
Vercel, which received a $9.3 billion valuation last year, provides developer tooling that helps build web applications and operates cloud infrastructure for hosting them
5
. The stolen data reportedly included information about hundreds of employees and API keys associated with GitHub repositories5
. Access to these repositories could enable supply chain vulnerabilities with potential to compromise numerous developers. However, Rauch confirmed that Next.js, Turbopack, AI SDK, and all Vercel-published npm packages remain uncompromised after a coordinated audit with GitHub, Microsoft, npm, and Socket3
. Vercel now defaults environment variable creation to "sensitive" and has deployed new dashboard features for managing variable settings3
. The company advises customers to audit activity logs, rotate API keys and tokens stored in non-sensitive environment variables, and implement credential rotation immediately2
.Summarized by
Navi
[1]
[2]
[3]
12 May 2026•Technology

31 Mar 2026•Technology

21 May 2026•Technology
