Monday, August 3, 2026

Compute & Cloud

Vercel confirms security breach via Context AI integration

Vercel confirmed a security breach originating from Context AI, which may affect hundreds of users across many organizations.

Vercel confirms security breach via Context AI integration
Photo: Vercel

Cloud app hosting platform Vercel confirmed on Sunday that hackers had breached its internal systems and customer data was stolen. According to Vercel, the breach originated from software maker Context AI, which specializes in AI evaluations and analytics. One of Vercel’s employees downloaded an app made by Context AI and connected it to their corporate Google account. The attackers utilized this connection, known as OAuth (an authentication protocol used to connect applications), to take over the employee’s Google account and gain unauthorized access to Vercel’s internal systems, including credentials that were not encrypted.

While Vercel stated that the hack may affect hundreds of users across many organizations, the company clarified that its Next.js and Turbopack projects were not affected. Both open-source projects are widely used by web and app developers. Vercel is currently investigating the incident and has contacted customers whose app data and keys were compromised. In a post on X, Vercel chief executive Guillermo Rauch advised customers to rotate any keys and credentials in their app deployments that are marked as “non-sensitive.” A spokesperson for Vercel noted that the company has not received any communication from the threat actor, such as a demand for ransom.

Meanwhile, a threat actor has claimed to represent the hacking group ShinyHunters and is selling the data online. The listing on a cybercriminal forum claims the hackers are selling access to customer API keys, source code, and database data stolen from Vercel. However, ShinyHunters told cybersecurity news site Bleeping Computer that they are not involved in this incident.

The breach has broader implications for Context AI, which confirmed on its website that it had a breach in March involving its Context AI Office Suite consumer app. The app allows users to automate actions and workflows across multiple third-party applications. Context AI, which initially notified only one customer, now believes the incident is likely broader than first thought and that hackers likely compromised OAuth tokens for some of its consumer users.

Why it matters

This security breach is the latest in a string of “supply chain” hacks that have targeted software developers, allowing hackers to steal credentials from a broad range of targets at once. By compromising software widely used across the web, attackers can gain further access to large amounts of data stored by other cloud giants.