Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
Vercel has confirmed a security incident in which attackers gained unauthorized entry into certain internal systems after exploiting a third-party AI tool, Context.ai, that was being used by one of its employees.
According to Vercel, the intruder leveraged the compromised Context.ai access to seize control of the employee’s Vercel Google Workspace account. That takeover then allowed the attacker to reach some Vercel environments and read environment variables that were not designated as sensitive.
The company emphasized that environment variables labeled as sensitive are stored in an encrypted format that prevents their contents from being read, and so far there is no indication those encrypted values were exposed. Vercel characterized the adversary as highly skilled, citing the attacker’s speed and deep knowledge of Vercel’s infrastructure.
Vercel said it has engaged Google-owned Mandiant and other cybersecurity firms to help with the inquiry, informed law enforcement, and is coordinating with Context.ai to establish the incident’s full extent.
A “limited subset” of Vercel customers had their credentials taken, the company said, and those affected have been contacted directly and instructed to rotate their credentials immediately. Vercel is continuing to investigate data that may have been removed and will notify customers if additional compromises are found.
The company is also advising Google Workspace administrators and account holders to check their environments for the following OAuth application identifier: 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com. Vercel has further recommended following standard security best practices and additional mitigations to reduce risk.
Vercel has not published a detailed breakdown of which internal systems were accessed, how many customers were impacted in total, or the identity of the intruder. Nonetheless, an actor using the ShinyHunters persona has claimed responsibility and listed the stolen data for sale with an asking price of $2 million.
In parallel reporting, Hudson Rock disclosed that a Context.ai employee was infected with Lumma Stealer in February 2026. That compromise may have been the catalyst for a wider supply-chain escalation, the report suggests. The harvested corporate credentials included Google Workspace logins plus keys and accounts for Supabase, Datadog, and Authkit.
The stolen dataset also contained the [email protected] account, which likely enabled privilege escalation and the bypassing of controls that allowed the attacker to pivot into Vercel’s environment. Hudson Rock assessed that the compromised user was a core member of Context.ai’s “context-inc” team at Vercel. Their activity logs reportedly show searches for and downloads of game exploitation tools - specifically Roblox “auto-farm” scripts and executors - which are known to be common delivery mechanisms for Lumma Stealer.
Vercel CEO Guillermo Rauch said in a post on X that the company has implemented extensive protections and increased monitoring, and has reviewed its supply chain to ensure projects such as Next.js, Turbopack, and other open-source efforts remain secure for the community.
Rauch added that Vercel has already introduced new dashboard features to help customers improve security posture, including an environment-variables overview page and an improved interface for creating and managing sensitive environment variables.