Vercel confirms breach following compromised third-party integration

Vercel has confirmed a security incident involving unauthorised access to parts of its internal systems. The entry point was a compromised third-party AI tool integrated through Google Workspace OAuth. The attackers leveraged that trusted integration path to gain limited internal access, affecting a small subset of systems and potentially exposing non-sensitive configuration data such as environment variables. Vercel says no evidence has been found that sensitive secrets or core production infrastructure were accessed, and that key services including the deployment platform and the Next.js ecosystem were unaffected. A threat group has claimed responsibility and alleged data theft, though Vercel has not verified the claims and the investigation continues. The company has revoked the affected integrations, engaged security experts and coordinated with law enforcement, and advises customers to review connected third-party applications and rotate credentials as a precaution.

What this means for your organisation

The breach did not happen in the platform but in an integration somebody connected. Most Norwegian organisations are exposed to the same pattern: OAuth connections to Microsoft 365 or Google Workspace are often approved by individual employees, persist until revoked, and rarely appear in any inventory. With the rapid uptake of AI tooling, the number of such connections has grown sharply in a short time. If you are a Vercel customer, the advice to rotate credentials applies to you directly.

Berigo recommends

  • Pull the list of OAuth applications with access to your Microsoft 365 or Google Workspace tenant and remove what is not in use.
  • Require administrator approval before new applications can gain access to company data.
  • If you are a Vercel customer, review connected applications and rotate credentials as the vendor advises.
  • Bring AI tools into your normal supplier assessment rather than treating them as ordinary productivity software.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch