Breach report
Vercel confirms customer environment variables were accessed via a compromised AI tool

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
An employee's Google Workspace account was taken over through a third-party AI app, Context.ai, giving access to non-sensitive environment variables for a subset of Vercel customers.
What happened
Vercel published a security bulletin on 19 April 2026 confirming unauthorised access to some internal systems. According to the bulletin, the chain began at Context.ai, a third-party AI tool. A Vercel employee had connected Context.ai's app to their corporate Google account; the attacker used that OAuth grant to take over the account, reached the employee's Vercel account, moved through internal systems and enumerated environment variables that customers had not marked as "sensitive". Context.ai told TechCrunch it had a breach of a consumer app in March.
On 23 April Vercel said it had found a small number of further customer accounts showing signs of earlier compromise, including infostealer malware (software that harvests saved passwords and tokens). Vercel says it has no evidence those compromises came from its own systems.
Confirmed vs. claimed
Confirmed by Vercel: non-sensitive environment variables for a limited subset of customers were accessed. Variables marked sensitive, Vercel's npm packages, and the Next.js and Turbopack projects were not affected. Vercel estimated the incident may affect hundreds of users across many organisations, TechCrunch reported.
Claimed and disputed: a forum seller claiming to represent ShinyHunters offered customer API keys, source code and database data. ShinyHunters denied involvement, according to TechCrunch citing BleepingComputer. None of the sources we reviewed addresses impact on developers in any particular country, including India.
Who is affected
Vercel customers whose projects stored secrets as non-sensitive environment variables, and anyone whose services rely on those keys.
What to do
- Rotate every environment variable not marked sensitive, then mark secrets as sensitive.
- Turn on multi-factor authentication using an authenticator app or passkey.
- Review account activity logs and recent deployments; set Deployment Protection to at least Standard and rotate its tokens.
- Check database and API logs for use of rotated keys.
- Audit which third-party apps hold OAuth access to staff Google or Microsoft accounts.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026