The company is known for developing Next.js, a widely used React framework, and for offering services such as serverless functions, edge computing, and CI/CD pipelines that enable developers to build, preview, and deploy applications.
The company said a limited subset of customers was affected by a security breach
Services not impacted
“ShinyHunters” posted on BreachForums but threat actors linked to recent attacks attributed to the ShinyHunters extortion gang have denied to BleepingComputer that they are involved in this incident.
Vercel is actively investigating, and has engaged incident response experts to help investigate and remediate
Vercel says it is taking steps to protect its customers, advising them to review environment variables, use its sensitive environment variable feature, and to rotate secrets if needed.
In messages shared on Telegram, the threat actor also claimed they were in contact with Vercel regarding the incident and that they discussed an alleged ransom demand of $2 million.
Our investigation has revealed that the incident originated from a third-party AI tool whose Google Workspace OAuth app was the subject of a broader compromise, potentially affecting hundreds of its users across many organizations.
We are publishing the following IOC to support the wider community in the investigation and vetting of potential malicious activity in their environments. We recommend that Google Workspace Administrators and Google Account owners check for usage of this app immediately.
Me too! Also interested in if the TA was actually SH or just another group that had motive to impersonate them them given the disavowal from SH. Not that I trust ShinyHunters to be transparent about their activities.
We now know that the compromised app was context.ai:
Several important takeaways in this update from Vercel CEO Guillermo Rauch:
The attacker moved from a compromised Google Workspace account to other Vercel infrastructure.
The attacker had access to “non-sensitive” environment variables, which are not encrypted at rest. The attacker had access to these.
Vercel is still claiming that only a “quite limited” set of users was impacted. Unclear why that’s so. Customers known to be impacted are being contacted.
Mandiant and other firms are working incident response.
It appears the compromise took place last month, targeting an application that they end-of-lifed. But they (and Crowdstrike) didn’t discover that user OAuth tokens had been compromised.
Vercel is not a Context customer, but it appears at least one Vercel employee signed up for the AI Office Suite using their Vercel enterprise account and granted “Allow All” permissions. Vercel’s internal OAuth configurations appear to have allowed this action to grant these broad permissions in Vercel’s enterprise Google Workspace.
If you were using context.ai’s Office Suite, you should review all account activity for connected services.
Logs indicate the user was actively searching for and downloading game exploits, specifically Roblox “auto-farm” scripts and executors. These types of malicious downloads are notorious vectors for Lumma stealer deployments.
This single infection led to a massive amount of corporate credentials falling directly into the hands of hackers. Notably, a query of Hudson Rock’s extensive cybercrime database reveals that Context.ai only has a single infostealer infection on record, this exact employee from a month prior to the incident.
Updates from Vercel. Looks like there was a prior compromise.
Second, we have identified a small number of customer accounts with signs of compromise that appear to be separate from the April 2026 incident. Based on our investigation to date, these compromises do not appear to have originated on Vercel systems. We have already contacted those accounts and provided them with specific corrective actions to remediate potential risk. This activity does not appear to be a continuation or expansion of the April incident, nor does it appear to be evidence of an earlier Vercel security incident.
More context from CEO Guillermo Rauch:
The team performed an in-depth analysis to search for root causes and to better understand the behavior of the threat actor.
We cast a very wide net, pulling and processing nearly a petabyte of logs of the entire Vercel Network and API, extending well beyond the initial Context[.]ai compromise.
We now understand that the threat actor has been active beyond that startup’s compromise. Threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers.
Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables.