Historical disclosure revision 1
Disclosures and evidence
Revision 1 of 1 · Evidence cutoff Apr 24, 2026, 11:59 PM UTC
0 prior statements preserved · 15 statements added. Attributed source statements retain the source’s qualifications.
What the company disclosed
Vercel stated: “We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems. We are actively investigating, and we have engaged incident response experts to help investigate and remediate. We have notified law enforcement and will update this page as the investigation progresses.”
Affected organizations and relationships
Vercel stated: “The incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used that access to take over the employee's individual Vercel Google Workspace account, which enabled them to gain access to that employee’s Vercel account. From there, they were able to pivot into a Vercel environment, and subsequently maneuvered through systems to enumerate and decrypt non-sensitive environment variables.”
Reported data impact
Vercel stated: “Initially we identified a limited subset of customers whose non-sensitive environment variables stored on Vercel (those that decrypt to plaintext) were compromised. We reached out to that subset and recommended an immediate rotation of credentials.”
Vercel stated: “First, we have identified a small number of additional accounts that were compromised as part of this incident, and we have notified the affected customers.”
Vercel stated: “In collaboration with GitHub, Microsoft, npm, and Socket, our security team has confirmed that no npm packages published by Vercel have been compromised. There is no evidence of tampering, and we believe the supply chain remains safe.”
Response
Vercel stated: “Deleting your Vercel projects or account is not sufficient to eliminate risk. Compromised secrets may still provide access to production systems, so you must rotate them before deleting your projects or account.”
Vercel stated: “Review and rotate environment variables that were not marked as “sensitive.” Those values (API keys, tokens, database credentials, signing keys, etc.) should be treated as potentially exposed and rotated as a priority.”
Vercel stated: “Take advantage of the sensitive environment variables feature so that secret values are protected from being read in the future.”
Vercel stated: “Review the activity log for your account and environments for suspicious activity. You can review activity logs in the dashboard or via the CLI .”
Vercel stated: “Rotate your Deployment Protection tokens , if set.”
Vercel stated: “We are publishing the following IOC to support the wider community in the investigation and vetting of potential malicious activity in their environments. We recommend that Google Workspace Administrators and Google Account owners check for usage of this app immediately.”
Dates and disclosures
Vercel stated: “24 Apr 2026”
Vercel stated: “| April 20, 5:32 PM PST | Validated npm packages are not compromised , added guidance for multi-factor authentication , shipped product enhancements .”
Qualifications and uncertainty
Vercel stated: “Second, we have identified a small number of customer accounts with signs of compromise that appear to be separate from the April 2026 incident. Based on our investigation to date, these compromises do not appear to have originated on Vercel systems. We have already contacted those accounts and provided them with specific corrective actions to remediate potential risk. This activity does not appear to be a continuation or expansion of the April incident , nor does it appear to be evidence of an earlier Vercel security incident.”
Vercel stated: “Our investigation has revealed that the incident originated from a small, third-party AI tool whose Google Workspace OAuth app was the subject of a broader compromise, potentially affecting its hundreds of users across many organizations.”
Disclosure sources and provenance
- Vercel Updated April 24, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:00 PM UTC · Retained Oct 7, 2026, 6:00 PM UTC
- Current captured representation; historical byte snapshots are unknown.
Evidence limitations
- Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
- Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.