Skip to content

Vercel

Disclosed Apr 19, 20265 months agoConfirmed

Official notice

Breach at AI app maker Context AI led to theft of Vercel customer credentials

A Vercel employee connected Context AI's app to a corporate Google account; attackers who breached Context AI used that OAuth link to take over the account and reach internal systems holding unencrypted customer credentials. Vercel notified affected customers and advised rotating keys.

What is known

People affectedNot stated in the sources we have
DisclosedApr 19, 2026
DiscoveredApr 2026
AttackSupply chain
Data exposedAPI keys, Credentials and tokens, Source code
SectorTech · US
StatusConfirmed

Sources

Source
App host Vercel says it was hacked and customer data stolentechcrunch.com · News
Vercel April 2026 security incidentvercel.com · Official notice
Vercel confirms breach as hackers claim to be selling stolen datableepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalApr 19
ResearchtotalApr 19
History of this record
  • 2026-09-25 · summary: Vercel said attackers hijacked an employee's Google Workspace account through a compromised Context.ai OAuth app and accessed internal systems, stealing API keys, app credentials and other data of hundreds of users across many organizations to A Vercel employee connected Context AI's app to a corporate Google account; attackers who breached Context AI used that OAuth link to take over the account and reach internal systems holding unencrypted customer credentials. Vercel notified · seed source
  • 2026-09-25 · title: Vercel breached via Context.ai OAuth app, customer secrets stolen to Breach at AI app maker Context AI led to theft of Vercel customer credentials · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Vercel

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.