Back to Feed
BreachesApr 20, 2026

Vercel Employee's AI Tool Access Led to Data Breach

Vercel employee's compromised AI tool access enabled OAuth token theft and data breach.

Summary

A Vercel employee's credentials were compromised, granting attackers access to AI tools and the ability to steal OAuth tokens that led to a data breach. Security researchers highlight that stolen OAuth tokens have become a primary attack vector for lateral movement and unauthorized access. The incident underscores the expanding attack surface created by AI-assisted development tools and token-based authentication.

Indicators of Compromise

  • malware — OAuth token theft

Entities

Vercel (vendor)OAuth (technology)AI tools (technology)