top of page
perceptive_background_267k.jpg

Vercel Finds More Compromised Accounts in Context.ai-Linked Breach

Published:

23 April 2026 at 08:40:00

Alert date:

23 April 2026 at 10:01:03

Source:

thehackernews.com

Click to open the original link from this advisory

Cloud & Virtualization, Data Breach & Exfiltration, Identity & Access, Supply Chain & Dependencies

Vercel discovered additional compromised customer accounts in a security incident linked to Context.ai that enabled unauthorized access to internal systems. The company expanded its investigation to include more compromise indicators and reviewed network requests. This represents an ongoing data breach affecting multiple customer accounts with potential for unauthorized system access.

Technical details

The breach originated from a compromise of Context.ai after being used by a Vercel employee. The attacker gained control of the employee's Google Workspace account and used it to access their Vercel account. From there, they pivoted into Vercel's environment and maneuvered through systems to enumerate and decrypt non-sensitive environment variables. Investigation revealed that a Context.ai employee was infected with Lumma Stealer malware in February 2026 after searching for Roblox auto-farm scripts and game exploit executors, which may have been the initial infection point. The attack involved OAuth integrations that can inherit trust from users and organizations, allowing attackers to avoid some security controls.

Mitigation steps:

Vercel has notified affected parties in both cases of compromise. Context.ai has deprecated the AI Office Suite. Organizations should review OAuth integrations and implement controls for direct account compromise, focus on rapid scoping and blast-radius reduction rather than just prevention, and be aware of shadow AI usage where employees use unauthorized AI tools without formal IT review.

Affected products:

Vercel
Context.ai
Context AI Office Suite
Google Workspace
Next.js framework

Related links:

Related CVE's:

Related threat actors:

IOC's:

Lumma Stealer malware

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page