// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

Vercel

DISCLOSED 2026-05-12 · STOLEN CREDS

In April 2026, Vercel disclosed a breach where an attacker used OAuth tokens stolen from Context.ai via Lumma Stealer malware to access Vercel internal systems and customer environment variables. The attack chain started with a Context.ai employee downloading Roblox auto-farm scripts, leading to a two-month dwell time and eventual exposure of credentials for AWS, Azure,...

The record

What we know

Disclosed
2026-05-12
Attack vector
Stolen Creds
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the Vercel disclosure. It updates if new public reporting emerges. All tracked breaches →

Vercel just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →