The cloud platform Vercel, used by developers to host web applications, says hackers breached its systems in an attempt to sell stolen data.
The breach came through a compromised third-party AI tool called
Context.ai that was in use by a Vercel employee.
“The attacker used that access to take over the employee's Vercel Google Workspace account, which enabled them to gain access to some Vercel environments and environment variables that were not marked as ‘sensitive,’”
the company wrote in a security bulletin.
Vercel added that the attacker was “highly sophisticated based on their operational velocity and detailed understanding of Vercel's systems.”
The San Francisco company says it has called in the troops to get to the bottom of the attack, including Google subsidiary Mandiant and other cybersecurity firms, industry peers, law enforcement, and
Context.ai. It notified “a limited subset of customers” whose credentials were compromised.
“We continue to investigate whether and what data was exfiltrated,” the company said, “and we will contact customers if we discover further evidence of compromise.”
—AN