Application hosting company Vercel disclosed that customer data was stolen after attackers compromised an employee account, an intrusion the company attributed to an earlier breach at Context AI, a vendor that builds evaluation and analytics tooling for AI models.
Context AI confirmed a March breach involving its Context AI Office Suite consumer application. Attackers used access gained there to hijack a Vercel employee account and extract customer information from Vercel systems. Vercel stated the incident may affect hundreds of users across many organizations and warned of potential downstream exposure reaching further into the technology sector, since Vercel customers host applications that hold their own end-user data.
The chain illustrates a pattern security teams have flagged as AI tooling proliferates inside engineering organizations. Analytics and evaluation platforms require broad access to model inputs, outputs, and often the accounts that operate them, which makes them high-value intermediate targets. A single compromised vendor in that layer reaches multiple downstream companies without needing to breach any of them directly.
A separate incident followed similar mechanics. Mercor, a three-year-old company valued at $10 billion that supplies expert-generated training data to AI developers including Anthropic, OpenAI, and Meta, confirmed a breach that may have exposed company and user data. That intrusion was linked to a supply chain attack involving LiteLLM, a widely deployed open source library applications use to connect to AI services.
Source: TechCrunch - https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai/
