Sev0AI security incidents, tracked

All incidents / Supply chain and access

Compromised AI tool Context.ai used as a pivot into Vercel

Vercel, disclosed Apr 2026. Supply chain and access Data exposed High

Attackers compromised AI productivity vendor Context.ai, then used an OAuth token from a Vercel employee who had granted the tool broad Google Workspace access to reach some Vercel environments and read environment variables.

Disclosed
Apr 2026
Organization
Vercel
Vendor
Unknown
Product
Context.ai
Type of AI
Work assistant
How it happened
Supply chain and access: Stolen token or key
Harm
Data exposed
Data involved
Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
  2. https://www.darkreading.com/application-security/vercel-employees-ai-tool-access-data-breach

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Compromised AI tool Context.ai used as a pivot into Vercel", https://sev0.fyi/incidents/2026-04-01-context-ai-vercel-oauth/