Vercel, a cloud development platform, experienced a security incident in April 2026. The breach was a supply chain attack originating from their third-party AI tool, Context.ai. Threat actors, identified as ShinyHunters, claimed admin access to internal systems and are reportedly selling stolen data.
The breach primarily exposed internal Vercel systems, including internal database access keys, portions of source code, non-sensitive environment variables, API keys, GitHub tokens, and NPM details. There is no evidence that sensitive customer data, SSN, medical, or financial data was involved. The specific number of affected individuals has not been disclosed, though Vercel described the impact as affecting a "limited subset of customers." There have been no reported official notifications to individuals or state Attorney General filings.
Details can emerge later as investigations progress, and notices to affected parties may be delayed.