## Vercel Compromise
In April 2026, Vercel suffered a security breach originating from a compromised third-party AI tool whose Google Workspace OAuth app was part of a broader attack affecting hundreds of users across multiple organizations.
## Attack Implications
Attackers gained unauthorized access to a limited subset of customer data, including potential exposure of non-sensitive environment variables such as API keys, tokens, and database credentials, while environment variables explicitly marked as “sensitive” in Vercel remained protected.
## Vercel Operational Status
Vercel’s services stayed operational throughout the incident, and the company engaged incident response experts and notified law enforcement. Vercel customers are advised to review their account activity logs, rotate any exposed environment variables, and audit their Google Workspace for the malicious OAuth app (`110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com`).
The IONIX research team is tracking the situation and update on any developments.
References:

