📰 Full Story
Vercel, the U.S.-based cloud platform that hosts and deploys web applications and maintains Next.js, disclosed a security incident on April 18–20, 2026 after attackers gained unauthorized access to certain internal systems.
The company says the intrusion originated from a compromised third‑party AI tool, Context.ai, whose Google Workspace OAuth app was breached.
Attackers used that foothold to take over an employee Google Workspace account and pivot into select Vercel environments, enumerating environment variables not marked as “sensitive.” Vercel says sensitive variables are encrypted at rest and show no evidence of being read.
The company has identified a limited subset of affected customers, engaged Google‑owned Mandiant and other responders, notified law enforcement, and published an IOC (OAuth app ID: 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com). A threat actor claiming the ShinyHunters persona has posted alleged employee records and is offering stolen data for about $2 million on underground forums; those claims remain partly unverified.
Vercel urged customers to review activity logs, rotate non‑sensitive environment variables and deployment tokens, enable sensitive variable protections, and audit Google Workspace for the identified OAuth app.







💬 Commentary