Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Vercel Context.ai OAuth Breach 2026: How a Forgotten…
Breach analysis Incident: 19 Apr 2026

Vercel Context.ai OAuth Breach 2026: How a Forgotten AI App’s Stolen Token Exposed Customer Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 12 min read
On this page

On 19 April 2026, the cloud platform Vercel disclosed that an attacker had reached its internal systems and read environment variables belonging to a limited subset of customers. The attack did not start at Vercel. It started at Context.ai, a small AI start-up whose consumer "AI Office Suite" at least one Vercel employee had signed up for with a corporate Google account and granted it full access. When Context.ai's AWS environment was breached, the attacker took OAuth tokens for its users, used one to take over the employee's Vercel Google Workspace account, then pivoted into Vercel and decrypted customer environment variables that had not been marked "sensitive". Hudson Rock traced the chain back further, to a Lumma infostealer infection on a Context.ai employee's computer in February 2026. It shows how an unmanaged AI app holding a long-lived OAuth grant can become a path into a much larger organisation.

Key takeaways

  • Vercel published its security bulletin on 19 April 2026, including the Google OAuth client ID of the compromised third-party app as an indicator of compromise.
  • Context.ai says it stopped unauthorised access to the AWS environment behind its consumer AI Office Suite in March 2026, and later found the attacker "likely compromised OAuth tokens for some of our consumer users".
  • Identities abused: a Context.ai employee's credentials (stolen by Lumma Stealer, according to Hudson Rock), the Context.ai Google Workspace OAuth app and its user tokens, a Vercel employee's Google Workspace account, and then Vercel internal access used to decrypt customer environment variables.
  • Exposed data: customer environment variables not flagged as sensitive, which decrypt to plaintext. Vercel says it has no evidence that sensitive environment variables were accessed, and that no npm packages it publishes were compromised.
  • Lesson: third-party OAuth grants, especially to AI tools employees try on their own, are non-human identities that need an owner, a scope review and an expiry.

At a glance

Organisation(s)Vercel; Context.ai (AI Office Suite); a limited subset of Vercel customers
WhenContext.ai employee infected with an infostealer in February 2026 (Hudson Rock); Context.ai AWS breach stopped in March 2026; Vercel disclosure 19 April 2026, with updates to 24 April 2026
AttackerUnattributed. A seller using the ShinyHunters name claimed the attack on a cybercrime forum, but people linked to ShinyHunters denied involvement to BleepingComputer, and a Google Threat Intelligence analyst suggested an impostor
Entry pointA stolen OAuth token for Context.ai's Google Workspace app, granted by a Vercel employee using their corporate account
Identities abusedContext.ai employee credentials and cloud access, the Context.ai OAuth app and its user tokens, a Vercel employee's Google Workspace account, Vercel internal access to environment variables
ImpactNon-sensitive environment variables of a limited subset of Vercel customers read in plaintext; Vercel has not published a customer count
CategoryNHI (OAuth app and tokens, application secrets), third-party AI app supply chain

What happened

Vercel's bulletin says: "The incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used that access to take over the employee's individual Vercel Google Workspace account." From there, Vercel says, the attacker got into a Vercel environment and moved through its systems to enumerate and decrypt environment variables that were not marked as sensitive. Vercel described the attacker as "highly sophisticated based on their operational velocity and in-depth understanding of Vercel's product API surface."

Context.ai's own statement, published on its website on Sunday 19 April 2026 and no longer available there, filled in the upstream part. According to TechCrunch and CyberScoop, the company confirmed a breach in March involving its consumer AI Office Suite app, in which the attacker reached its AWS environment. Context.ai said the hackers "likely compromised OAuth tokens for some of our consumer users", as quoted by TechCrunch, and that it now believed the incident was broader than first thought. Context.ai and Vercel said their investigations, aided by CrowdStrike and Mandiant, were continuing.

The Vercel link was a single sign-up. According to CyberScoop's account of the statement, Vercel is not a Context customer, but a Vercel employee was using the AI Office Suite and granted it full access. The OAuth grant stayed valid after Context.ai itself was breached.

Hudson Rock, an infostealer intelligence firm, reported on 20 April that a Context.ai employee had been infected with Lumma Stealer in February 2026. The stolen data included Google Workspace logins and keys or logins for Supabase, Datadog and Authkit. Hudson Rock said the employee had been downloading Roblox "auto-farm" scripts, a common Lumma lure, and wrote that the infection "likely resulted in this massive supply chain escalation." Context.ai has not said how the attacker got into its AWS environment, so the link between that infection and the March intrusion remains Hudson Rock's assessment.

The incident became public when a seller claiming to be ShinyHunters offered Vercel data on a cybercrime forum. BleepingComputer reported claims of access keys, source code, database data, internal deployments, some npm and GitHub tokens and 580 employee records, with a reported asking price of $2 million. These are the seller's claims. Vercel's own findings describe exposed customer environment variables, and it says it worked with GitHub, Microsoft, npm and Socket to confirm that "no npm packages published by Vercel have been compromised."

Vercel chief executive Guillermo Rauch said the attackers "moved with surprising velocity and in-depth understanding of Vercel", according to CyberScoop, and Trend Micro quoted him as suspecting the group was "significantly accelerated by AI." In a later update, reported by The Hacker News on 23 April, Vercel said it had also found a small number of customer accounts with signs of compromise that appeared to be separate from this incident and did not appear to originate on Vercel systems.

Timeline

DateEvent
February 2026A Context.ai employee's computer is infected with Lumma Stealer; Google Workspace and developer tool credentials are stolen (Hudson Rock).
March 2026Context.ai identifies and stops unauthorised access to the AWS environment hosting the consumer product; OAuth tokens for some consumer users are likely stolen.
Before 19 April 2026The attacker uses a stolen OAuth token to take over a Vercel employee's Google Workspace account, pivots into Vercel and decrypts non-sensitive customer environment variables. Exact dates have not been published.
19 April 2026Vercel publishes its bulletin and the OAuth app IOC; Context.ai confirms the breach in a statement on its website (since removed); BleepingComputer reports the forum sale claim.
20 April 2026Vercel clarifies which credentials were affected and confirms its npm packages are safe; Hudson Rock publishes its infostealer findings.
22 to 23 April 2026Vercel publishes further investigation findings, including a small number of additional compromised accounts and separate, unrelated compromises.

How it happened: the identity attack path

  1. Vendor employee credentials stolen. According to Hudson Rock, Lumma Stealer took a Context.ai employee's Google Workspace login and keys for Supabase, Datadog and Authkit in February 2026.
  2. Vendor cloud breached. Context.ai says an unauthorised actor accessed the AWS environment behind its consumer AI Office Suite. Context.ai has not published how that access was obtained.
  3. OAuth tokens taken in bulk. The attacker likely took OAuth tokens that consumer users had granted to the Context.ai Google Workspace app. Vercel says the app's compromise potentially affected "its hundreds of users across many organizations".
  4. Corporate account taken over. One token belonged to a Vercel employee who had signed up with a work account and granted it full access. The attacker used it to take over that Google Workspace account without needing the employee's password or MFA.
  5. Pivot into the platform. Vercel says the attacker moved from the Workspace account into a Vercel environment, then through its systems.
  6. Secrets read at scale. The attacker enumerated and decrypted customer environment variables that were not flagged as sensitive, the kind of values that often hold API keys, database URLs and service tokens.

Impact

  • Customer secrets: Vercel says a limited subset of customers had non-sensitive environment variables, "those that decrypt to plaintext", compromised. It contacted those customers and asked them to rotate credentials. It has not published a number.
  • Sensitive variables: Vercel says it has no evidence that environment variables marked sensitive were accessed.
  • Software supply chain: Vercel says no npm packages it publishes were compromised, and TechCrunch reported that the Next.js and Turbopack open source projects were not affected.
  • Wider reach: Vercel's IOC notice says the compromised OAuth app potentially affected hundreds of users across many organisations, and it urged Google Workspace administrators to check for it. Trend Micro reports that a Vercel customer was notified of a leaked OpenAI API key on 10 April 2026, before Vercel's disclosure.
  • Attacker claims: the forum seller claimed source code, database data, npm and GitHub tokens and employee records. Vercel has not confirmed these claims.

What this means for NHI governance

Every step that mattered here ran on a non-human identity. The OAuth grant from a Vercel employee to Context.ai was a standing, delegated credential held by a third party. It was issued by one person, never reviewed, and stayed valid long after anyone needed it. When the third party's cloud was breached, the attacker did not need to phish anyone at Vercel. They simply used a token that already had the permissions they wanted.

This is the same pattern as the Salesloft Drift and Klue incidents, with one difference: the app was an AI tool picked up by an individual, not a sanctioned integration. AI productivity tools ask for broad scopes because they want to read mail, files and calendars to be useful. Full access on a corporate account turns a personal experiment into an organisational supply chain dependency that security teams may not even know exists. Context.ai itself says Vercel was not a customer.

The second lesson is about secrets at rest. Customer environment variables are machine credentials: API keys, database strings, signing secrets. Vercel encrypts all of them at rest, but those not flagged as sensitive can be decrypted by internal systems, and an attacker with internal access could do the same. Vercel has since said it is improving environment variable management "with stronger defaults". For customers, the practical point is that any secret stored in a platform without the strongest protection option should be assumed readable by someone who compromises that platform.

Recommendations

  • Search for the IOC now. Check Google Workspace for the Context.ai OAuth client ID Vercel published, revoke it, and review what the account behind any grant accessed.
  • Govern third-party OAuth apps. Restrict which apps users can grant access to corporate accounts, require admin approval for broad scopes, and review grants regularly. The SaaS OAuth App Governance Guide sets out a workable process.
  • Find shadow AI tools. Inventory AI apps and agents connected to your identity provider, mail and file stores, including trials. See the Shadow AI Agent Discovery Guide.
  • Give grants an owner and an end date. Revoke OAuth tokens when a user stops using an app, when a vendor reports a breach or when the app is retired, following the NHI Lifecycle Management Guide.
  • Mark platform secrets as sensitive. Use the strongest secret storage option your hosting platform offers, and keep high-value keys in a dedicated secrets manager, as covered in the Secrets Management Guide.
  • Rotate after a platform breach. If you were notified, rotate every exposed key and token and check provider logs for use. Challenges of Rotating NHIs explains why this needs planning.
  • Keep corporate credentials off unmanaged devices. The chain began with an infostealer on a vendor employee's machine; ask critical vendors how they protect developer and admin credentials.

Frequently asked questions

What happened in the Vercel breach?

In April 2026 Vercel disclosed that an attacker used an OAuth token stolen from Context.ai, a third-party AI tool, to take over a Vercel employee's Google Workspace account. The attacker then pivoted into Vercel's systems and decrypted environment variables of a limited subset of customers that were not marked as sensitive.

How was Context.ai involved in the Vercel hack?

A Vercel employee had signed up for Context.ai's consumer AI Office Suite with a corporate Google account and granted it full access. When attackers breached Context.ai's AWS environment in March 2026, they likely stole OAuth tokens for its users, including that employee's token.

Were Vercel customers affected?

Yes, a limited subset. Vercel says their non-sensitive environment variables were compromised and it contacted them to rotate credentials. It says there is no evidence sensitive environment variables were accessed and that no npm packages it publishes were compromised.

Salesloft Drift OAuth token breach · Klue OAuth supply chain breach · Cyberhaven Chrome extension breach · SaaS OAuth App Governance Guide · Shadow AI Agent Discovery Guide

How NHI Mgmt Group can help

OAuth grants to AI tools, platform secrets and delegated tokens are non-human identities, and the Vercel incident shows what happens when nobody owns them. Our NHI Foundation Level Training Course helps teams discover, govern and revoke these identities before a vendor breach turns them into an attack path.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org