AI/TLDR

Vercel · 2026-04-20 · major

Vercel Breached via Context.ai Supply-Chain Attack — Customer Credentials Exposed, Database Listed at $2M

Lumma Stealer infected a Context.ai employee in February; attackers pivoted via stolen Google OAuth to Vercel's internal systems, exposing customer credentials. ShinyHunters impersonators listed the database for $2M on BreachForums.

Vercel breach tied to Context AI hack

A compromised AI analytics tool became the entry point for a breach affecting Vercel — the web platform used by millions of developers.

What is it?

Vercel announced it was breached via Context.ai, an AI analytics SaaS. A Context.ai employee's device was infected with Lumma Stealer malware in February 2026, giving attackers access to their Google Workspace OAuth credentials.

How does it work?

Attackers used the 'support@context.ai' account they compromised to pivot to Vercel. A Vercel employee had connected their enterprise Google account to Context.ai with 'Allow All' permissions, providing the bridge. The threat actor accessed Vercel's internal systems through this compromised account and exfiltrated non-sensitive environment variables and customer account data.

Why does it matter?

Threat actors posted the Vercel database for sale at $2M on BreachForums. While Vercel confirmed 'sensitive' environment variables (encrypted) were not exposed, customers were advised to rotate any credentials marked as 'non-sensitive'. The incident illustrates how AI tooling integrations create new OAuth pivot points in developer infrastructure.

Who is it for?

Any Vercel user who integrated Context.ai should audit their OAuth connections and rotate environment variable secrets immediately.

Sources · 4 outlets

Tags

  • supply-chain
  • oauth
  • data-breach
  • vercel
  • shinyhunters
  • lumma-stealer

← All releases · Learn AI