Web infrastructure provider Vercel disclosed in April 2026 that attackers reached certain internal systems after compromising Context.ai, a third-party artificial intelligence office tool used by one of its employees. The company said the intruder took over that employee's Vercel Google Workspace account, then reached some Vercel environments and environment variables that carried no "sensitive" designation.

Vercel stated that variables marked sensitive are stored in encrypted form and that no evidence showed the attacker read those values. The company described the threat actor as sophisticated, citing operational speed and detailed knowledge of Vercel systems. Vercel engaged Mandiant and other security firms, notified law enforcement, and worked with Context.ai to determine the scope of the intrusion.

A limited subset of customers had credentials compromised. Vercel contacted those customers directly and urged immediate credential rotation. The company also advised Google Workspace administrators to review OAuth grants, enable multi-factor authentication, audit environment variables holding secrets, and rotate deployment protection tokens.

Context.ai published its own bulletin describing a March 2026 incident in which it identified and blocked unauthorized access to its AWS environment. The company later determined that the attacker likely used a compromised OAuth token to reach Vercel's Google Workspace. Context.ai said a Vercel employee had signed up for its AI office suite using a Vercel enterprise account and granted "Allow All" permissions.

Hudson Rock reported that a Context.ai employee was infected with Lumma Stealer in February 2026, which may have started the supply chain escalation. Vercel CEO Guillermo Rauch said the company deployed added protection and monitoring and analyzed its supply chain. A later update said work with Microsoft, GitHub, npm, and Socket found no evidence that Vercel npm packages were compromised.

Source: The Hacker News - https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html