All Breaches
April 19, 2026 Verified Sensitive Record Cloud Computing

Vercel Context.ai OAuth 2026 Data Breach

The Vercel Context.ai OAuth 2026 data breach began with compromise of the Google Workspace OAuth application belonging to third-party AI tool Context.ai and led to unauthorized access to certain Vercel internal systems and environment variables for a limited group of customers. Vercel disclosed the incident on April 19, 2026, and notified affected customers.

According to the company's updated investigation, the attacker took over a Vercel employee's Google Workspace account and then their Vercel account, pivoted into a Vercel environment, and enumerated and decrypted environment variables that resolved to plaintext because they were not marked sensitive. No exact customer, account, or variable total was published, so pwnCount and totalRecords remain zero as unknown.

How Was the Incident Confirmed?

Vercel's official security bulletin directly confirms unauthorized access to internal systems, the origin of the attack, and compromise of customer environment variables. The initial review identified a limited subset of customers; broader log and indicator analysis found a small number of additional compromised accounts within the same April incident. Vercel contacted those customers with corrective steps.

BleepingComputer reported the bulletin and the Vercel CEO's technical explanation, corroborating the Context.ai account takeover, environment-variable enumeration, and customer advice. It also described a forum user's claims about source code, database data, and employee records, but could not independently authenticate them. LeakData therefore does not treat those claims as confirmed scope.

What Customer Data Was Affected?

The verified class is customer environment variables stored on Vercel as “non-sensitive” and able to resolve to plaintext. An environment variable can be configuration, but users may also put API keys, access tokens, database credentials, or signing keys in it. Vercel advised customers to treat such values as potentially exposed and rotate them.

This list does not mean every affected customer stored every kind of secret. Vercel said customer environment variables marked sensitive are encrypted at rest; the incident progressed through values classified as non-sensitive and therefore readable. LeakData records the completed access to environment variables without inventing a count of particular keys used by the attacker.

How Did the Context.ai OAuth Chain Work?

Vercel says the Google Workspace OAuth application of a small third-party AI tool was compromised in a broader campaign. The attacker used that access to control the individual Google Workspace account of a Vercel employee who used the tool and then the employee's Vercel account. A pivot into the internal environment amplified the supply-chain effect of one account.

Vercel published the OAuth application identifier and urged Google Workspace administrators and account owners to check for use of the same app. The company assessed the actor as sophisticated based on operational speed and detailed knowledge of Vercel's product API surface and said it was working with Google Mandiant, other security firms, industry peers, and law enforcement.

How Many Customers Were Affected?

The bulletin uses “limited subset” and later “small number of additional accounts” but provides no exact figure. Vercel's overall customer base, deployment count, and platform users are not the breach total. LeakData therefore uses neither the forum's 580 employee records nor company size as pwnCount.

The expanded review also found signs of compromise in a small number of other customer accounts that appeared separate from the April incident and were assessed not to originate on Vercel systems. The company contacted those accounts but did not classify them as continuation of the April breach or an earlier Vercel security incident. LeakData does not combine the separate findings into this record.

Was the Software Supply Chain Affected?

Vercel confirmed through work with GitHub, Microsoft, npm, and Socket that no npm package published by Vercel was compromised and that there was no evidence of tampering. Next.js, Turbopack, and the company's other open-source projects remained safe. This record does not claim malicious package injection or impact to every deployment hosted on Vercel.

The company introduced an environment-variable overview and improvements for managing sensitive values. Customers should understand that deleting a project or account alone does not eliminate risk because a stolen secret may continue to provide access to an external production system. Potentially exposed values should be rotated first, followed by review of logs and connected services.

How Should This LeakData Record Be Read?

Because the precise initial-access date was not published, breachDate uses the official April 19, 2026 bulletin. The confirmed event is the Context.ai OAuth chain compromising an employee account, a pivot into the Vercel environment, and reading non-sensitive environment variables belonging to certain customers. The customer and record totals remain unknown.

Customers should treat API keys, tokens, database credentials, and signing keys stored in non-sensitive environment variables as potentially exposed and rotate them. Forum claims involving source code, databases, internal deployments, and 580 employee records were not confirmed by Vercel and are therefore excluded from data classes and numeric scope.

0
Affected Accounts
6
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

6
Non-sensitive environment variables
Potential api keys
Potential access tokens
Potential database credentials
Potential signing keys
Customer account access

Additional Information

Added DateJuly 27, 2026
Breach DateApril 19, 2026
Domainvercel.com
SourceContext.ai OAuth compromise leading to Vercel environment-variable access
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information