Vercel Hacked: Data Breach Tied to Third-Party AI Tool
Vercel Hacked: Data Breach Tied to Third-Party AI Tool
Vercel confirms a security incident after attackers exploited a third-party AI tool to access internal systems; only a small number of customers affected as experts investigate.
Vercel, the cloud development platform behind a popular front-end workflow, confirmed a security incident after attackers breached internal systems and stole data. The breach is linked to a compromised third-party AI tool, Context AI, which allowed unauthorised access to certain internal environments. Vercel stresses that services themselves were not affected and that the company is actively working with affected customers. A security bulletin notes that it has notified law enforcement and engaged incident-response experts to help investigate and remediate, with updates to follow as the investigation progresses.
The incident highlights a broader risk: attackers increasingly target AI tools to conduct supply-chain-style intrusions. In recent weeks, even major open-source AI projects such as Axios, LiteLLM, and Trivy have been compromised, ripple effects that can touch developers relying on these tools. The case also comes as AI models themselves become more capable in ways that could be exploited by hackers.
Executive messages suggest the attackers were highly capable and accelerated by AI, moving with notable velocity and an in-depth understanding of Vercel’s environment. While the immediate impact is limited to a small number of customers, the episode serves as a reminder to monitor third-party tool integrations closely and to tighten access controls around critical accounts, such as Google Workspace, used by staff.