Cloud development platform Vercel was hacked
The company says the attack originated from a compromised “third-party AI tool.”
The company says the attack originated from a compromised “third-party AI tool.”
by Terrence O'Brien
Apr 19, 2026, 7:54 PM UTC


Screenshot: The Verge
Terrence O'Brien
is the Verge’s weekend editor. He has over 18 years of experience, including 10 years as managing editor at Engadget.
Vercel, a major development platform that hosts and deploys web apps, was compromised, and the hackers are attempting to sell stolen data. A person claiming to be a member of ShinyHunters, which was behind the recent hack of Rockstar Games, posted some data online, including employee names, email addresses, and activity time stamps. Vercel confirmed in a post on X that a “security incident” had occurred, and that it impacted a “limited subset” of its customers. Vercel said that a compromised third-party AI tool was the avenue for attack, though it did not specify which third-party was involved.
Vercel encouraged administrators to review their activity logs for suspicious activity. It also suggested taking steps to “review and rotate environmental variables” as an extra precaution in case API keys, tokens, or other sensitive data were exposed. It ended its security bulletin by saying:
Our investigation has revealed that the incident originated from a third-party AI tool whose Google Workspace OAuth app was the subject of a broader compromise, potentially affecting hundreds of its users across many organizations.
We are publishing the following IOC to support the wider community in the investigation and vetting of potential malicious activity in their environments. We recommend that Google Workspace Administrators and Google Account owners check for usage of this app immediately.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
- Terrence O'Brien
The Verge Daily
A free daily digest of the news that matters most.
Related Articles
Kimi新论文:把KVCache玩成新商业模式了
< img id="wx_img" src="https://www.qbitai.com/wp-content/uploads/imgs/qbitai-logo-1.png" width="400" height="400"> 2026-04-19 ...
横扫全球15项SOTA!高德首个面向AGI的全栈具身技术体系大公开
< img id="wx_img" src="https://www.qbitai.com/wp-content/uploads/imgs/qbitai-logo-1.png" width="400" height="400"> 2026-04-19 ...
大模型架构的下半场
< img id="wx_img" src="https://www.qbitai.com/wp-content/uploads/imgs/qbitai-logo-1.png" width="400" height="400"> 大模型架构的下半场 2026-04-19 ...
高德发布全球首个面向AGI的全栈具身技术体系“ABot”:15项SOTA,构建持续进化的具身智能闭环
< img id="wx_img" src="https://www.qbitai.com/wp-content/uploads/imgs/qbitai-logo-1.png" width="400" height="400"> 2026-04-19 ...
