AI cloud company Vercel breached after employee grants AI tool ...
The culprit? An infostealer infection from a Roblox cheat download.
www.tomshardware.comVercel experienced a security breach in April 2026 stemming from a compromise at third-party AI tool Context.ai. A Vercel employee's excessive permissions to this tool via OAuth enabled attackers to hijack their Google Workspace account.[6]
The root cause traces to a February 2026 infostealer malware infection on a Context.ai employee's machine, likely from downloading Roblox cheats. This exposed OAuth tokens, allowing hackers to pivot through the Vercel employee's granted access to internal systems and non-sensitive environment variables.[2][3]
Attackers accessed limited customer credentials but not encrypted "sensitive" variables or core projects like Next.js. A threat actor (claiming ShinyHunters affiliation) advertised the data for $2 million, affecting hundreds of users across organizations.[5][7]
Vercel disclosed on April 19, engaged Mandiant for investigation, notified law enforcement and affected customers, and updated security practices. Context.ai confirmed its prior breach and broader OAuth token compromises.[3][4][6]
The culprit? An infostealer infection from a Roblox cheat download.
www.tomshardware.comAn OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk.
www.trendmicro.comContext.ai breach enabled Google Workspace takeover at Vercel, exposing limited customer credentials and prompting $2M data sale claim.
thehackernews.comFollowing the recent confirmation of the Vercel breach, where threat actors claimed to be actively selling stolen corporate data, Hudson Rock has identified the likely point of origin. Our cybercrime intelligence indicates that a very recent infostealer infection of an employee at a third-party vendor likely resulted in this massive supply chain escalation.
www.infostealers.comWe’ve identified a security incident that involved unauthorized access to certain internal Vercel systems.
vercel.comAn employee using a consumer app was breached after granting too many permissions.
www.cybersecuritydive.comVercel blamed its breach on an earlier hack at Context AI, which allowed hackers to hijack a Vercel employee's account to steal customer data.
techcrunch.com