AI Incidents
Back to incident register
Source reviewedSupply chainHigh

Vercel security incident originates with compromised AI tool Context.ai

According to Vercel, attackers compromised the third-party AI tool Context.ai, used it to take over an employee account, and moved into internal Vercel systems.

First observed
Apr 19, 2026, 2:00:00 AM
Disclosed
Apr 19, 2026, 2:00:00 AM
Status
Monitoring
Confidence
98%
Organization
Vercel, Context.ai, Google Workspace
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • Vercel traces the origin to Context.ai's compromised Google Workspace OAuth application.
  • The attacker took over an employee's Workspace account, reached the employee's Vercel account, and pivoted into internal systems.
  • A limited group of customers had readable environment variables that were not marked sensitive; Vercel notified affected customers.
  • Vercel found no compromise of its own npm packages.

Assessment

Interpretation, not observation

  • This is a third-party OAuth supply-chain incident; the source does not attribute the attacker's decisions to an autonomous model.

Impact

Impact

Unauthorized internal access, compromised accounts, and potentially exposed non-sensitive environment variables.

Response

Response

Vercel worked with incident-response firms and authorities, notified affected parties, published an indicator of compromise, and tightened product controls.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.