Vercel disclosed that attackers accessed some internal systems after compromising Context.ai, an AI productivity tool used by a Vercel employee, and abusing broad Google Workspace OAuth permissions granted to the app. Using a valid OAuth token, the attacker reportedly took over the employee’s corporate account and pivoted through single sign-on into internal resources, including issue trackers, admin tools, and certain company environments. Vercel said some internal data and customer environment variables were exposed, including a limited number of customer credentials and API keys that had been classified as non-sensitive but were still usable.
The company notified affected customers and told them to rotate credentials while it investigated with Mandiant, other external firms, and law enforcement. Context.ai separately said a March intrusion into its AWS environment involved compromised OAuth tokens affecting some consumer users, linking that earlier breach to the later access into Vercel. Reporting also said the stolen Vercel data was offered for sale for $2 million by actors claiming ties to ShinyHunters, though known members denied involvement, and the incident has intensified scrutiny of SaaS integrations with excessive OAuth scopes and enterprise SSO access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By April 20, 2026, Vercel disclosed that some internal systems had been accessed through the compromised third-party AI tool Context.ai and said a limited number of customer credentials were affected. The company notified impacted customers, advised them to rotate credentials, and said it was investigating with Mandiant, other external firms, and law enforcement.
After the intrusion, stolen Vercel data was advertised for sale on the dark web for $2 million by a group claiming affiliation with ShinyHunters. Reported ShinyHunters members denied involvement.
In April 2026, after a Vercel employee had authorized Context.ai with broad Google Workspace permissions, an attacker used a valid OAuth token to take over the employee's Google Workspace account and pivot via SSO into Vercel internal systems. The attacker accessed issue trackers, internal environments, admin tools, and environment variables, including some usable customer API keys that had been marked non-sensitive.
In March 2026, Context.ai said an attack led to unauthorized access to its AWS environment through compromised OAuth tokens, affecting some consumer users. This compromise later became the foothold used in the Vercel incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecoalitioninc.com
Open sourcehalborn.com
Open sourceinfostealers.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.