Cloud development platform Vercel disclosed on April 19, 2026 that an attacker gained unauthorized access to internal systems through a third-party artificial intelligence tool a single employee had connected to a corporate account.

The employee signed up for Context's AI Office Suite using a Vercel Google Workspace account and approved an Allow All permission scope during setup. That grant gave the application broad read access to the account rather than the narrow scope the product needed.

The compromise upstream came earlier. In February 2026 an employee at Context.ai holding sensitive access privileges was infected with Lumma infostealer malware after downloading game exploit files. The attacker used credentials harvested from that machine to reach Context customer integrations, then used the Vercel employee's OAuth grant to take over the Google Workspace account.

Credentials collected during the intrusion included Google Workspace logins along with keys and logins for Supabase, Datadog and Authkit. A threat actor claiming affiliation with the ShinyHunters group listed stolen Vercel material on BreachForums for $2 million in Bitcoin, describing API keys, source code and 580 employee records.

Downstream effects reached organizations hosting on the platform, including Web3, decentralized finance and software companies, several of which rotated credentials on an emergency basis.

Security researchers reviewing the incident pointed to OAuth sprawl as the underlying condition. Individual employees can grant lasting third-party access to corporate data without an approval step, and the resulting grants are rarely inventoried or revoked.

Source: The Hacker News - https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html