Vercel confirmed a significant security incident in April 2026, stemming from a compromised employee account. The breach originated via a third-party AI platform, Context.ai, whose Google Workspace OAuth app was compromised. This incident highlights the growing risks associated with interconnected third-party services.
Compromise Details
An attacker exploited a Vercel employee's compromised account on Context.ai to gain unauthorized access to Vercel's internal systems. The attack escalated through the employee's Vercel Google Workspace account.
