Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Shadow AI and OAuth grants: what identity teams missed at Vercel


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Vercel’s breach reportedly began with a compromised Google Workspace account approved through a third-party AI integration, then expanded through the same OAuth scopes the vendor used legitimately, according to Oleria Security. The incident shows that without usage-level visibility, approved access and attacker access can become operationally indistinguishable.

NHIMG editorial — based on content published by Oleria Security covering the Vercel breach and shadow AI access risk: The Vercel breach didn't break in. It walked in through a door you opened

By the numbers:

Questions worth separating out

Q: How should security teams govern third-party AI agents that use OAuth access?

A: Security teams should treat third-party AI agents as governed non-human identities, not informal integrations.

Q: Why do approved OAuth grants create hidden identity risk for enterprises?

A: Because the grant can be legitimate, durable, and still dangerous.

Q: What breaks when organisations rely on periodic access reviews for AI systems?

A: Periodic access reviews break when the identity scope changes between review cycles.

Practitioner guidance

  • Inventory all delegated AI and OAuth access Create a single register of every third-party AI tool, copilot, agent platform, and extension with access to identity providers, collaboration suites, source control, and cloud control planes.
  • Re-consent high-risk scopes and remove dormant grants Force review or re-consent for any integration with domain-wide delegation, deployment-level privileges, or write access to repositories and cloud systems.
  • Shift detections from permissions to usage Build alerting around unusual resource access, scope consumption, and changes in vendor behaviour rather than only on new grants.

What's in the full article

Oleria Security's full post covers the operational detail this post intentionally leaves for the source:

  • A deeper walkthrough of the Vercel access chain, including how the OAuth consent path was created and why it escaped central visibility.
  • The specific telemetry and identity-context signals Oleria says are needed to distinguish normal vendor activity from attacker activity.
  • A detailed breakdown of how the Identity Context Graph correlates human, non-human, and AI identities across systems.
  • The vendor's recommended response sequence for third-party AI compromise and access tracing.

👉 Read Oleria Security's analysis of the Vercel OAuth breach and shadow AI risk →

Shadow AI and OAuth grants: what identity teams missed at Vercel?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Approved OAuth access is now an NHI governance problem, not a convenience feature. The Vercel case shows that delegated access granted to a third-party AI tool can persist beyond the original business context and remain exploitable after the vendor is compromised. Identity teams cannot treat consent as a one-time event when the resulting token can be used to traverse internal systems. The practitioner conclusion is that consent, scope, and ongoing usage all need continuous governance.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when a misconfigured AI integration or trusted update path is exploited?

A: Accountability should sit with the control owners for identity, application delivery, and risk governance, not only with vulnerability management. If the path involved privileged credentials, build pipelines, or an AI integration, those owners must be part of the remediation and assurance model because the failure crossed multiple domains.

👉 Read our full editorial: Vercel OAuth breach shows how shadow AI turns identity into risk



   
ReplyQuote
Share: