Sev0

AI security incidents, tracked

All incidents / Supply chain and access

Compromised AI tool Context.ai used as a pivot into Vercel

Vercel, disclosed 19 Apr 2026 Supply chain and access Data exposed High

What happened

Attackers compromised AI productivity vendor Context.ai, then used an OAuth token from a Vercel employee who had granted the tool broad Google Workspace access to reach some Vercel environments and read environment variables.

Context.ai makes an AI office suite that connects to users' Google accounts. It had stopped an intrusion into its AWS environment in March, and later learned the attacker had also likely taken OAuth tokens, the stored permissions its app used to act on users' behalf. Reports trace the original compromise to infostealer malware on a Context.ai employee's laptop in February. One of the affected users was a Vercel employee who had signed up with a corporate Google Workspace account and granted broad access. The attacker used that token to take over the employee's Google Workspace account, moved from there into some Vercel internal environments and read environment variables that customers had not marked as sensitive, which can include API keys and database passwords. Vercel said variables marked sensitive are stored so they cannot be read, and it had no evidence those were accessed.

How it happened

Supply chain and access: Stolen token or key. Stolen or leaked access tokens, API keys or passwords were used to get in.

Sources do not say whose AI model was involved. The product was Context.ai, a type of work assistant.

Impact

Data was exposed. Data involved: credentials. The impact was confined to one organization and its users or customers.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It became public on 19 Apr 2026.

Vercel disclosed the incident on 19 April, contacted the affected subset of customers and told them to rotate credentials, brought in Mandiant and law enforcement, and said its services and open-source projects such as Next.js were unaffected. Context.ai published its own bulletin, engaged CrowdStrike and shut down the affected AWS environment.

Sources

  1. https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
  2. https://www.darkreading.com/application-security/vercel-employees-ai-tool-access-data-breach
  3. https://www.theregister.com/2026/04/20/vercel_context_ai_security_incident/

Related incidents

Cite as: Sev0, "Compromised AI tool Context.ai used as a pivot into Vercel", https://sev0.fyi/incidents/2026-04-19-context-ai-vercel-oauth/. Data for this record: incidents.json.