Web infrastructure provider Vercel disclosed in April 2026 that attackers gained unauthorized access to internal company systems after compromising Context.ai, a third-party artificial intelligence tool used by a Vercel employee. According to a security bulletin Vercel published, the employee had signed into the Context.ai browser extension using enterprise Google Workspace credentials and granted the tool broad "Allow All" permissions.

Attackers first breached Context.ai itself in March 2026, gaining access to its AWS environment and compromising OAuth tokens tied to some of its users, according to a security update Context.ai published. Investigators later found that a Context.ai employee had been infected with the Lumma Stealer malware in February 2026 after downloading unauthorized Roblox game scripts, according to research firm Hudson Rock. The stolen credentials reportedly included Google Workspace logins along with keys for other cloud services.

Vercel said the compromised OAuth access allowed the attacker to take over the employee's Google Workspace account and reach Vercel environments and environment variables not marked as "sensitive." The company said data marked sensitive is encrypted and it found no evidence that data was accessed. Vercel stated a "limited subset" of customers had credentials compromised and it contacted them directly to request credential rotation.

A threat actor using the ShinyHunters name claimed responsibility and advertised the stolen data for sale online, though Google Threat Intelligence Group said the actor may be impersonating that name. Vercel said it worked with Google-owned Mandiant, law enforcement, and other partners to investigate, and rolled out new dashboard tools for managing environment variables in response.

Source: The Hacker News -- https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html