Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and Customer Environment Variable Exposure
Vercel April 2026 Security Incident (TL-2026-0394), also tracked as Vercel April 2026 Incident, is a high-severity data breach, first published 2026-04-20. It is attributed to ShinyHunters (France) with low confidence, affects Vercel Vercel Cloud Platform (deployments and environment variables), maps to 14 MITRE ATT&CK techniques (T1078.004, T1087.004, T1098.001), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-0394
- Threat ID
- TL-2026-0394
- Also known as
- Vercel April 2026 Incident, Vercel Context.ai Breach, Vercel ShinyHunters Extortion, Vercel OAuth Compromise
- Severity
- HIGH
- Status
- MONITORING
- Category
- DATA_BREACH
- First published
- 2026-04-20
- Last reviewed
- 2026-04-20
- Attribution
- ShinyHunters
- Attribution confidence
- LOW
- Nation-state nexus
- France
- Motivation
- FINANCIAL
- Target sectors
- technology, saas, cryptocurrency, e-commerce, media, developer-tools, startups, financial
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 13
Vercel disclosed on 2026-04-19 that a third-party compromise of Context.ai — an AI tool authorized in a Vercel employee's Google Workspace — let an attacker hijack that employee account via a malicious OAuth application (client ID 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com) and read a limited subset of customer environment variables that were not marked as 'sensitive.' A threat actor posting under the 'ShinyHunters' alias is selling stolen access keys, source code, database data, NPM/GitHub tokens and 580 employee records on an underground forum and has demanded a USD 2 million extortion payment; Vercel engaged Mandiant and notified law enforcement.
How Vercel April 2026 Security Incident works
INCIDENT OVERVIEW
On 2026-04-19 at 11:04 AM PST, cloud development and hosting platform Vercel published a security bulletin confirming a security incident affecting a limited subset of customers. An updated bulletin at 6:01 PM PST disclosed the root cause: compromise of Context.ai, a third-party AI tool used by a Vercel employee. Leveraging that access, the attacker hijacked the employee's Google Workspace account via a malicious OAuth application and pivoted into internal Vercel environments, reading customer environment variables that had not been marked as 'sensitive.' Vercel has engaged Mandiant for incident response, notified law enforcement, and deployed additional protection measures; services remain operational.
ATTACK CHAIN
This incident is a textbook illicit-consent-grant / third-party SaaS OAuth abuse chain. Step 1: attackers compromised Context.ai (an upstream SaaS used by a single Vercel employee); the scope of that breach is still under joint investigation. Step 2: the attacker abused the OAuth trust the employee had granted Context.ai in Google Workspace to take over the Google Workspace account. Vercel is publishing the specific malicious OAuth client ID — 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com — as an IOC so other Workspace administrators can hunt for it. Step 3: with Google-backed SSO access the attacker reached Vercel's production tenants, enumerated environments, and read environment variables not marked as 'sensitive.' Step 4: the attacker staged data (including internal Linear records used as proof of compromise) and, on 2026-04-19, listed the stolen material for sale on an underground hacking forum while simultaneously demanding a USD 2,000,000 extortion payment from Vercel.
DATA IMPACT — WHAT WAS AND WAS NOT EXPOSED
Exposed: environment variables that customers had NOT marked as 'sensitive' — which in practice commonly contain third-party API keys, database URLs, webhook signing keys, feature-flag tokens, and other secrets that developers treated as configuration. Also exposed: 580 Vercel employee records containing names, Vercel email addresses, account status and activity timestamps (published by the actor as a proof-of-breach sample). The actor further claims to hold NPM tokens, GitHub tokens, access keys, source code and database data.
NOT exposed (per Vercel's assessment as of 2026-04-20): environment variables marked 'sensitive' are stored in a form that prevents read access and Vercel states there is no evidence those values were accessed. Open-source projects maintained by Vercel — including Next.js and Turbopack — are confirmed unaffected. Only a 'limited subset' of customers had credentials exposed; those customers have been directly notified.
ATTRIBUTION
The actor is posting under the 'ShinyHunters' persona, but known ShinyHunters members have publicly denied involvement to reporters. The incident therefore appears to be the work of either a copycat, a loosely affiliated individual reusing the brand, or a distinct crew operating under the name. Vercel assesses the actor as 'highly sophisticated based on operational velocity and detailed understanding of Vercel's systems.' Motivation is financial, evidenced by the USD 2M ransom demand and the underground forum sale listing. Attribution confidence is LOW given the public dispute over actor identity.
DOWNSTREAM TENANT RISK
Vercel hosts a very large share of the Next.js, serverless and edge-deployed web, including major SaaS, e-commerce, media and cryptocurrency properties. Any tenant whose non-sensitive environment variables contained live secrets (third-party API keys, database credentials, webhook signing keys, crypto-project admin keys, etc.) must treat those secrets as compromised and rotate them immediately. Public reporting has specifically flagged crypto projects as exposed. Strategically the incident mirrors the Snowflake and prior SaaS-to-SaaS breach patterns: a single compromised upstream integration cascades into identity takeover and downstream tenant data exposure whenever OAuth application governance is weak.
MITRE ATT&CK techniques used in TL-2026-0394
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship
Discovery
T1087.004 Account Discovery: Cloud Account; T1526 Cloud Service Discovery
Persistence
T1098.001 Account Manipulation: Additional Cloud Credentials
Collection
T1213 Data from Information Repositories; T1213.003 Data from Information Repositories: Code Repositories
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Exfiltration
T1567 Exfiltration Over Web Service; T1567.002 Exfiltration to Cloud Storage
Resource Development
T1585.003 Establish Accounts: Cloud Accounts
Impact
Affected products and versions in Vercel April 2026 Security Incident
- Vercel — Vercel Cloud Platform (deployments and environment variables)
Vulnerable versions: All tenant environments containing non-sensitive environment variables during the 2026-04 incident window
Fixed in: N/A — post-incident hardening; customer action required to rotate secrets and mark variables as sensitive - Context.ai — Context.ai third-party AI tool (Google Workspace OAuth integration)
Vulnerable versions: All installations during the 2026-04 incident window
Fixed in: Investigation ongoing per Vercel bulletin; upstream remediation pending vendor disclosure - Google — Google Workspace OAuth application governance
Vulnerable versions: Any tenant permitting unrestricted third-party OAuth app installation by end users
Fixed in: Admin-controlled OAuth app access configuration with allowlist policy
Remediation for Vercel April 2026 Security Incident
Patches
- No vendor software patch is required — this is a configuration and identity-hygiene incident, not a CVE
- Track Context.ai's own forthcoming disclosure for upstream root-cause and remediation details
Immediate actions
- Google Workspace administrators: search 'Third-Party App Access' logs and Admin console for OAuth client ID 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com — revoke and block immediately
- Vercel customers: treat every non-sensitive environment variable as compromised for the pre-2026-04-19 window; rotate all API keys, database URLs, NPM tokens, GitHub tokens and third-party SaaS secrets that were stored unencrypted
- Review Vercel account activity logs and deployment history for anomalous deployments, token creations, or API calls between 2026-03-01 and 2026-04-20
- Enable Vercel Deployment Protection at Standard level or higher and rotate Deployment Protection tokens
- Force re-authentication and reset session tokens for all Google Workspace users authorized to access Vercel
- Inventory any Context.ai OAuth grants across the organization and revoke until Context.ai discloses remediation
Workarounds
- Temporarily disable all third-party OAuth apps in Google Workspace that are not business-critical
- Temporarily freeze Vercel deployment tokens and enforce rotation before re-enabling
- Apply IP allowlisting where supported for Vercel admin and API actions
Longer-term hardening
- Mark every secret-bearing environment variable as 'sensitive' in Vercel going forward and adopt tooling to enforce this at PR-time
- Implement Google Workspace 'OAuth app access control' with an allowlist policy and admin-only installation of third-party apps
- Require verified-publisher status and manual admin approval for any third-party OAuth app requesting Workspace scopes
- Deploy CASB / SSPM monitoring for anomalous OAuth grants, new third-party app installs and abnormal token use across SaaS tenants
- Move platform secrets out of environment variables into a secrets manager with short-lived credentials where feasible
- Establish a break-glass procedure for identity compromise affecting developer, SRE and platform-engineering employees
Weaknesses (CWE) in Vercel April 2026 Security Incident
CWE-287, CWE-522, CWE-798, CWE-1244, CWE-1395
Timeline of Vercel April 2026 Security Incident
- Context.ai compromise window opens (precise date under joint investigation by Context.ai and Vercel) — attacker obtains OAuth access to Context.ai customer Workspaces
- Attacker leverages Context.ai OAuth grant to take over Vercel employee's Google Workspace account via malicious OAuth client ID 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com
- Attacker pivots from Google Workspace SSO into Vercel internal environments and begins reading non-sensitive customer environment variables
- Attacker stages 580 employee records, internal Linear data, access keys, NPM and GitHub tokens for sale and begins extortion contact with Vercel
- Known ShinyHunters members deny involvement when contacted by reporters — attribution remains disputed, likely copycat or loose affiliate
- Vercel engages Mandiant incident response, notifies law enforcement, and begins direct notification of affected customers
- Vercel publishes updated bulletin at 6:01 PM PST naming Context.ai compromise as root cause and enumerating customer remediation steps
- Vercel publishes initial KB bulletin at 11:04 AM PST including malicious OAuth client ID as IOC
- Actor posts the stolen data for sale on an underground hacking forum under the ShinyHunters persona and demands USD 2,000,000
- Vercel bulletin last updated — investigation ongoing; services remain operational; open-source projects (Next.js, Turbopack) confirmed unaffected
- As of 2026-05-29, the Vercel intrusion itself is contained (access cut off ~Apr 19, Mandiant engaged, customers notified, forum listing reportedly pulled), but Vercel's bulletin is still officially ongoing and exposed non-sensitive env-var secrets remain a live risk until rotated. The ShinyHunters-branded 2026 extortion cluster stays highly active (Instructure/Canvas, 7-Eleven, Cushman & Wakefield), so the actor and OAuth-abuse tooling persist.
Sources cited for Vercel April 2026 Security Incident
- Vercel April 2026 Security Incident — Knowledge Base Bulletin
- Vercel confirms breach as hackers claim to be selling stolen data
- Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
- Vercel confirms security incident as hackers claim to sell internal access
- Vercel Confirmed Unauthorized Access to Its Internal Systems — $2M Ransom
- Vercel Security Breach Raises Concerns for Crypto Projects
- Vercel Security Breach — Analysis
- Google Workspace — OAuth app access control (Admin Help)
Threats related to Vercel April 2026 Security Incident
- Vercel April 2026 Security Incident — Context.ai OAuth Supply Chain Compromise Exposing Employee Records, Plaintext Environment Variables, and npm/GitHub Tokens
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign
Detection coverage for TL-2026-0394
As of 2026-04-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0394 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.