Vercel released a security incident analysis, indicating that some of its internal systems suffered unauthorized access. The incident stemmed from a compromise of Context.ai, a third-party AI tool used by an employee. The attacker used this compromise to take over the employee's Google Workspace account and access some environment configuration data. The initial impact is that a small number of customers may have had their environment variables (such as API keys and tokens) not marked as "sensitive" leaked. Affected users have been notified and advised to immediately rotate their credentials. Currently, there is no evidence that data or supply chains marked as "sensitive" (such as npm packages) have been tampered with. Vercel stated that the attacker possessed a high level of technical skill and has launched an investigation in conjunction with Mandiant and several other security agencies, and has filed a police report. Vercel emphasized that platform services are still operating normally and officially recommends that users enable multi-factor authentication, fully rotate potentially compromised environment variables, and check account activity logs and deployment records to prevent further risks.