Cloud platform Vercel confirmed on April 19, 2026 that it was breached through a third-party AI tool called Context.ai. The intrusion began when Context.ai was infected with information-stealing malware around February 2026, which captured authentication credentials tied to a Vercel employee's account.
The employee had connected Context AI to his Vercel Enterprise Google Workspace account and granted the AI tool full read access to his Google Drive as part of normal use. Attackers used the stolen credentials to bypass multi-factor authentication and access the employee's Google Workspace account, then pivoted into Vercel's internal systems.
Once inside, the attackers enumerated and decrypted non-sensitive environment variables, including API keys and database credentials that had been stored in plaintext on Vercel's platform. Vercel said no sensitive environment variables or npm packages were compromised and that its open-source projects were unaffected. Threat actors later listed a database described as taken from Vercel for sale at $2 million on the hacking forum BreachForums.
Security researchers who reviewed the incident described it as a supply-chain attack that originated entirely outside Vercel's own infrastructure, illustrating how broad permissions granted to third-party AI tools can create an indirect path into otherwise secure enterprise systems. Vercel has since revoked the compromised credentials and rotated affected environment variables.
Source: Help Net Security - https://www.helpnetsecurity.com/2026/04/20/vercel-breached/
