DEFENCE / RADAR

Public snapshot

Vercel·Technology / SaaS·

Vercel third-party OAuth application opened a path to customer data.

Vercel said attackers reached internal systems through Context.ai, a third-party AI tool. Public reporting supports customer data access; the exact root cause and financial impact remain unestablished.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Entry path: Third-party access
Consequence
Reported: Customer data was accessed.
Scope
The complete extent is not established.

1)Incident fact sheet

Organization
Vercel
Industry
Technology / SaaS
Disclosed
Entry path
Third-party access
Third party
Context.ai
Affected asset
internal Vercel systems and environment variables
Data involved
Credentials · Authentication tokens
Reported impact
Data exposure
Attached evidence
8 independent domains · 9 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved third-party access.

    ConfidenceSecondary
    Exact excerpt

    the breach stemmed from the compromise of a third-party AI tool's Google Workspace OAuth application

    bleepingcomputer.com · Apr 19
    E1
  2. 02

    Third party

    Context.ai

    ConfidenceSecondary
    Exact excerpt

    The incident originated with a compromise of Context.ai, a third-party AI tool

    helpnetsecurity.com · Apr 20
    E2
  3. 03

    Reached

    internal Vercel systems and environment variables

    ConfidenceSecondary
    Exact excerpt

    gain access to some of Vercel’s internal systems, including credentials that were not encrypted

    techcrunch.com · Apr 20
    E3
  4. 04

    Observed

    Customer data was accessed.

    ConfidenceProbable
    Exact excerpt

    accessed customer data

    techcrunch.com · Apr 20
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • Whether any ransom or extortion payment was made
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that grant third-party OAuth applications access to cloud workspaces, credentials, or environment variables.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
22
Data breach / intrusion
Confirmed share
40%
52 confirmed · 78 reported
Display family
Data breach
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

9 attached sources across 8 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E3, E4
    techcrunch.comApp host Vercel says it was hacked and customer data stolenEstablished press · Apr 20 · Cited
    Established pressCited
    Exact excerpt
    customer credentials
  2. E1
    bleepingcomputer.comVercel confirms breach as hackers claim to be selling stolen dataSpecialist reporting · Apr 19 · Cited
    Specialist reportingCited
    Exact excerpt
    the breach stemmed from the compromise of a third-party AI tool's Google Workspace OAuth application
  3. E2
    helpnetsecurity.comVercel breached via compromised third-party AI tool - Help Net SecurityOther public report · Apr 20 · Cited
    Other public reportCited
    Exact excerpt
    The incident originated with a compromise of Context.ai, a third-party AI tool
  4. S4
    theregister.comNext.js developer Vercel warns customer creds compromisedEstablished press · Apr 20 · Attached
    Established pressAttached
  5. S5
    ox.securitySupply Chain Attack Hits Vercel: User Data is Being Sold on BreachForums For $2MSecurity research · Apr 20 · Attached
    Security researchAttached
  6. S6
    trendmicro.comThe Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables | Trend MicroSecurity research · Apr 20 · Attached
    Security researchAttached
Show all 9 sourcesShow the first six sources
  1. S7
    forbes.comHow A Roblox Cheat Download Triggered A $2 Million Hack At VercelEstablished press · Apr 21 · Attached
    Established pressAttached
  2. S8
    techcrunch.comVercel says some of its customers' data was stolen prior to its recent hack | TechCrunchEstablished press · Apr 23 · Attached
    Established pressAttached
    Exact excerpt
    valuable tokens like keys to Vercel accounts
  3. S9
    pushsecurity.comUnpacking the Vercel breach: Shadow AI and OAuth sprawlSecurity research · Apr 23 · Attached
    Security researchAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →