On April 19th, 2026, Vercel disclosed a security incident involving unauthorized access to their internal systems. According to their incident report, the attacker compromised an employee’s Google Workspace account via a third-party AI tool named Context.ai, who have since confirmed that their consumer-focused AI Office Suite environment was indeed compromised. This incident is in effect a double supply chain attack, where access to Context.ai was leveraged to gain access to their customers, including Vercel, and then Vercel’s customers.
Context.ai disclosed that they determined that OAuth tokens for some consumer users were likely compromised as a result of this incident. According to their statement, at least one Vercel employee had authorized the affected OAuth application with broad (“Allow All”) permissions, which enabled the attacker to leverage the stolen token to access Vercel’s Google Workspace.
Public reporting by Hudson Rock has noted that a recent infostealer infection of a Context.ai employee may have been leveraged to gain access to Context.ai's internal systems and ultimately acquire the OAuth application credentials, but this remains unconfirmed.
This activity hasn’t been attributed to a specific threat actor, but an actor claiming to be associated with ShinyHunters has claimed responsibility for Vercel’s incident. However, these claims remain unverified, and the group may have been impersonated by a copycat.