Cloud Platform Vercel Confirms Data Leak After Hack Linked to AI Tool Breach
Vercel is widely used for front-end deployment and cloud hosting, and leaked customer credentials could put projects and related services at risk. The incident was traced to a third-party AI tool used by an employee. AI company Context suffered an infostealer attack about two months earlier and is suspected of having provided a gateway into Vercel’s internal systems.
Vercel recently confirmed that only “limited” user information had been accessed. It contacted affected customers and advised them to update or rotate their credentials. A seller on a hacker forum offered the related data for $2 million. Vercel has not disclosed the exact dates of the intrusion, the Context breach or the discovery of the leak, leaving the full timeline unclear.
All Coverage
3 original reportsThe Backstory
The history behind this eventAI Security Risks Draw Scrutiny as Vercel and Mercor Are Attacked, Mozilla Uses Claude to Patch Flaws
Generative AI tools are increasingly being integrated into software development, recruitment and browser maintenance, widening the attack surface across third-party services and software supply chains. Cloud development platform Vercel and AI interview platform Mercor were both affected, underscoring the need for companies adopting AI to review vendor permissions, data access and the security of software dependencies.
Reports published on April 22 revealed that Vercel suffered a data breach after third-party AI tool Context.ai was hacked. Mercor was also affected by a LiteLLM supply-chain attack. Neither case disclosed the amount of losses. Separately, Mozilla used Anthropic’s Claude Mythos model to identify and patch 271 vulnerabilities in Firefox, showing that AI can create security risks while also strengthening defenses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.