Vercel says a Context.ai breach exposed limited customer credentials and internal systems
Guillermo Rauch said a compromised Context.ai account let an attacker take over a Vercel employee's Google Workspace account and reach some Vercel environments; Vercel said only a limited subset of customers were affected.
From the sources (22 posts)
@darkwebinformerThe CEO of Vercel has responded to the breach.
@gergelyoroszThe Vercel security breach is a reminder that each and every SaaS tool your team uses IS a security risk of its own - especially if they need broad data access to eg email, internet docs etc (many AI tools do just this) Security teams onbo
@andrewcurran_Vercel: 'We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI.'
@intcyberdigest🚨 According to sample data we received from the Vercel breach, Vercel's CEO Guillermo Rauch was last seen on March 3, 2026. Who is running the company? The threat actor told us Vercel's security was poor, and consistent with Vercel's own d
@theoFwiw, I am impressed with how Vercel has handled this incident so far. They’re taking it seriously. Notifying affected parties within minutes of identification. Being realistic about what they do and don’t know. They’re clearly more worri
@8teapiRT @rauchg: Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situa…
@cointelegraph🚨 JUST IN: Vercel confirms its security breach originated from a third-party AI tool whose Google Workspace OAuth app was compromised. It urges Google Workspace Administrators to check for its usage immediately.
@theoRT @rauchg: Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situa…
@joshkaleWhat do Vercel, Rockstar Games, Anthropic, and Adobe have in common? They've all been breached in the last 19 days... Vercel was this morning. Someone is currently selling their source code on BreachForums for $2 million. The attackers got
@suppvalenRT @shawmakesmagic: This vercel thing is a fucking apocalypse Hundreds possibly thousands of npm, pypi etc tokens not to mention tents of…
@theoRT @jaimeblascob: Google has deleted the account but I’m confident the third party AI tool that vercel mentioned in the blog post is contex…
@hackingdaveRT @GergelyOrosz: The Vercel security breach is a reminder that each and every SaaS tool your team uses IS a security risk of its own - esp…
@lulumeserveyA good example — Don’t wait for the investigation to be complete. Don’t let PR and legal scare you into silence. Don’t hide between deflections People just need to know, at a minimum, that you’re personally leading the effort, that you ca
@theblockcoWeb3 hosting backbone Vercel confirms breach as supposed hacker demands $2 million ransom
@degeneratenewsNEW: @vercel CEO @rauchg SAYS "WE BELIEVE THE ATTACKING GROUP [THAT TARGETED @vercel] TO BE HIGHLY SOPHISTICATED AND, I STRONGLY SUSPECT, SIGNIFICANTLY ACCELERATED BY AI. THEY MOVED WITH SURPRISING VELOCITY AND IN-DEPTH UNDERSTANDING OF VER
@officer_secretRT @officer_secret: Vercel has been hacked! According to @acceleratooooor , here's how to triage: 1. Go to 2. Se…
@hesamationthe API keys you didn’t let Claude read are being sold for $2M by Vercel hackers.
@thehackersnews🔥 Vercel disclosed a BREACH after an attacker used a compromised 3rd-party AI tool to take over an employee account. Some internal systems, non-sensitive variables, and limited customer credentials were exposed. 🔗 Read →
@officer_secretVercel has been hacked! According to @acceleratooooor , here's how to triage: 1. Go to 2. Security → Access and data control → API controls → App access control → Manage Third-Party App Access 3. Search for clien
@officer_secretA friendly reminder that even NON VERCEL USERS are at risk: > next.js is owned by vercel > "npx skills add" is vercel > as well an entire ecosystem of frontend and AI backbone packages Someone on BreachForums claims to have vercel internal
@officer_secretThe third party AI tool was context[.]ai To safeguard your org from attacks like this, highly recommend asking your Google workspace admin to restrict "unconfigured third-party apps" to only be able to request basic info needed 👇 Here's t
@rauchgHere's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called