Cyber Incident Victim: Vercel
Date:
Apr 2026
Location:
United States of America
Summary
Vercel disclosed that an employee’s Google Workspace account was compromised after the third‑party AI tool Context.ai was infected with Lumma Stealer, giving attackers inherited OAuth access and a two‑month dwell time before the breach was discovered when the stolen data appeared for sale. The attackers used the hijacked employee account to access Vercel environments, exfiltrating employee records, access keys, API keys, GitHub and NPM tokens, and non‑sensitive environment variables, while also uncovering evidence of earlier, unrelated compromises of a small number of customer accounts. Vercel disclosed the breach, notified affected customers, and engaged incident response and law‑enforcement teams.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In February 2026 an employee of the third‑party AI tool Context.ai had their computer infected with the Lumma Stealer malware, which remained undetected for approximately two months. The compromised Context.ai system was later used by a Vercel employee who granted the tool broad OAuth permissions to access their Google Workspace account. Attackers exploited the stolen OAuth token to seize control of the employee’s Google Workspace credentials and from there pivoted into Vercel’s internal environment, where they began enumerative API activity focused on non‑sensitive environment variables that were not encrypted at rest. The intrusion persisted undetected until early April 2026 when the threat actors advertised the stolen data for sale on BreachForums for two million dollars, prompting Vercel to disclose the incident on April 19. Vercel’s initial statement described the breach as originating from a compromised employee Google Workspace account via Context.ai and noted a two‑month dwell time before discovery. On April 23 Vercel updated its security incident page, revealing that investigators had uncovered evidence of prior unauthorized activity affecting a small number of customer accounts that predated the April event and was independent of it, potentially resulting from social engineering, malware or other methods, and that the company had notified those affected customers and engaged incident response experts and law enforcement.

The data exposed in the main April incident included employee records, access keys, API keys, GitHub and NPM tokens, and non‑sensitive environment variables, with the threat actor claiming to have obtained 580 employee records plus the aforementioned keys and source code; Vercel characterized the affected customer subset as limited and did not disclose exact numbers. Vercel services remained operational throughout the incident, and the company confirmed that it had disclosed more customer accounts compromised by the April event without specifying further details. Context.ai publicly confirmed its own earlier breach, and both Vercel and Context.ai indicated that the incident could have broader implications, suggesting that additional victims might emerge as the investigation continued. The company’s response involved notifying known affected parties, coordinating with external incident response specialists, and working with law enforcement to pursue attribution and potential disruption of the attackers. No further specifics about the scope of customer impact or the exact timing of the prior compromise were disclosed beyond what was stated in the official updates.
