Vercel Says Internal Systems Hit in Breach
The incident came to light on Sunday and the company says it has brought in an incident response provider to investigate the intrusion. Details of the intrusion are scant at this point.

The incident came to light on Sunday and the company says it has brought in an incident response provider to investigate the intrusion. Details of the intrusion are scant at this point.
April 21, 2026 | 3 min read

UPDATE--Vercel, a widely used cloud platform for developing and deploying apps, has disclosed a breach of its internal systems, and says a “limited subset of customers” is affected.
The incident came to light on Sunday and the company says it has brought in an incident response provider to investigate the intrusion. The company recommends that customers check activity logs for suspicious activity and also rotate environmental variables as a precaution. Vercek also suggests that customers use its sensitive environmental variables feature to mark things such as API keys as sensitive, which then causes Vercel to store them in an unreadable format.
Vercel said the intrusion was related to the compromise of a third-party app, Context.ai, which one of Vercel's employees used.
"The incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used that access to take over the employee's Vercel Google Workspace account, which enabled them to gain access to some Vercel environments and environment variables that were not marked as 'sensitive', the Vercel post says.
"Environment variables marked as "sensitive" in Vercel are stored in a manner that prevents them from being read, and we currently do not have evidence that those values were accessed. We assess the attacker as highly sophisticated based on their operational velocity and detailed understanding of Vercel's systems."
The company also said on Monday that it had worked with Microsoft, GitHub, and npm, and Socket to verify that the company's npm packages were not compromised.
Vercel did not initially identify the app but after Context released its own alert, Vercel identified Context. Given that the intrusion originated with a third-party app, there may well be other related incidents emerging in the coming hours or days.
“We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems. We are actively investigating, and we have engaged incident response experts to help investigate and remediate. We have notified law enforcement and will update this page as the investigation progresses,” the company said in the original statement.
“At this time, we have identified a limited subset of customers that were impacted and are engaging with them directly.”
Vercel provides a wide range of services for developers and enterprises, and has a number of offerings that are focused on agentic AI workloads.
Vercel did not specify which of its systems were compromised or how many of its customers are affected, but said it has contacted the customers that it has identified as being affected.
"Initially we identified a limited subset of customers whose Vercel credentials were compromised. We reached out to that subset and recommended an immediate rotation of credentials. If you have not been contacted, we do not have reason to believe that your Vercel credentials or personal data have been compromised at this time," the company said.
Later on Sunday, Context, an AI provider, published a security notice related to the Vercel intrusion, saying that it had identified and halted an incident in March that turned out to be connected to Vercel's incident. Context officials said an attacker gained access to the company's AWS environment and compromised OAuth tokens for some of Context's consumer users.
"Today, based on information provided by Vercel and some additional internal investigation, we learned that, during the incident last month, the unauthorized actor also likely compromised OAuth tokens for some of our consumer users. We also learned that the unauthorized actor appears to have used a compromised OAuth token to access Vercel’s Google Workspace," the Context statement says.
"Vercel is not a Context customer, but it appears at least one Vercel employee signed up for the AI Office Suite using their Vercel enterprise account and granted 'Allow All' permissions. Vercel’s internal OAuth configurations appear to have allowed this action to grant these broad permissions in Vercel’s enterprise Google Workspace."
This story was updated on April 19 to add information about the source of the intrusion; on April 20 to add information from Context; and on April 21 to add more information from Vercel.
April 21, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.