DEFENCE / RADAR

Public snapshot

Vercel·Technology / SaaS·

Customer environment variables were exposed.

Vercel disclosed an OAuth-token supply-chain compromise involving access to internal systems and customer environment variables. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: Non-sensitive environment variables were not encrypted at rest
Consequence
Reported: Customer environment variables were exposed.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Vercel
Industry
Technology / SaaS
Disclosed
Entry path
Third-party access
Third party
Context.ai
Affected asset
Vercel internal systems and customer project environment variables
Country
US
Data involved
Authentication tokens · Credentials · Business Confidential
Reported impact
Data exposure
Attached evidence
10 independent domains · 10 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved third-party access.

    ConfidenceSecondary
    Exact excerpt

    the breach stemmed from the compromise of a third-party AI tool's Google Workspace OAuth application

    bleepingcomputer.com · Apr 19
    E1
  2. 02

    Reported cause

    Non-sensitive environment variables were not encrypted at rest

    ConfidenceSecondary
    Exact excerpt

    not marked as sensitive and therefore not encrypted at rest

    bleepingcomputer.com · Apr 19
    E2
  3. 03

    Third party

    Context.ai

    ConfidenceSecondary
    Exact excerpt

    naming Context.ai as the compromised third party

    trendmicro.com · Apr 20
    E3
  4. 04

    Reached

    Vercel internal systems and customer project environment variables

    ConfidenceSecondary
    Exact excerpt

    access environment variables that were not marked as sensitive

    bleepingcomputer.com · Apr 19
    E4
  5. 05

    Observed

    Customer environment variables were exposed.

    ConfidenceProbable
    Exact excerpt

    exposing environment variables for an undisclosed but reportedly limited subset of customer projects

    trendmicro.com · Apr 20
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The supplied record does not establish the full scope of exposed data
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that authorize third-party OAuth applications to access customer environments.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
56
Supply chain / third party
Confirmed share
40%
52 confirmed · 78 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

10 attached sources across 10 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E3, E5
    trendmicro.comThe Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables | Trend MicroOther public report · Apr 20 · Cited
    Other public reportCited
    Exact excerpt
    environment variables for an undisclosed but reportedly limited subset of customer projects
  2. E1, E2, E4
    bleepingcomputer.comVercel confirms breach as hackers claim to be selling stolen dataSpecialist reporting · Apr 19 · Cited
    Specialist reportingCited
    Exact excerpt
    not marked as sensitive and therefore not encrypted at rest
  3. S3
    techcrunch.comVercel says some of its customers' data was stolen prior to its recent hack | TechCrunchEstablished press · Apr 23 · Attached
    Established pressAttached
    Exact excerpt
    The San Francisco-based app and website hosting company
  4. S4
    cyberscoop.comVercel attack fallout expands to more customers and third-party systems | CyberScoopOther public report · Apr 23 · Attached
    Other public reportAttached
    Exact excerpt
    valuable tokens like keys to Vercel accounts
  5. S5
    osto.oneVercel Breach 2026 | Roblox Cheat Script to $2M LossOther public report · May 01 · Attached
    Other public reportAttached
  6. S6
    securebulletin.comVercel Data Breach: ShinyHunters Exploit OAuth Supply Chain Attack to Steal Customer Credentials for $2M Sale - Secure BulletinOther public report · May 07 · Attached
    Other public reportAttached
Show all 10 sourcesShow the first six sources
  1. S7
    assured.co.ukAI Autopsy: Vercel Breach Shows SaaS Integrations Are the New Attack Path • AssuredOther public report · May 12 · Attached
    Other public reportAttached
  2. S8
    thorstenmeyerai.comThe Roblox Cheat That Broke Vercel. - Thorsten Meyer AIOther public report · May 12 · Attached
    Other public reportAttached
  3. S9
    cybersecurity-insiders.comVercel Breach: OAuth Sprawl Turns AI Security CriticalOther public report · May 13 · Attached
    Other public reportAttached
  4. S10
    nhimg.orgVercel breach shows SaaS supply chain risk is now identity riskOther public report · May 25 · Attached
    Other public reportAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →