Breaking news

Vercel Breach Exposes Customer Credentials In Supply Chain Attack

Incident Overview

Cloud hosting platform Vercel confirmed a security breach over the weekend that exposed sensitive customer credentials. Stolen data is reportedly being offered for sale online, raising concerns about vulnerabilities in software supply chains.

Method Of Breach

According to the company, the incident originated from an external tool developed by Context AI. An employee installed the application and connected it to a corporate Google account via OAuth. Attackers exploited this access to take control of the account and retrieve unencrypted credentials stored within internal systems.

Impact On Services

Core products, including Next.js and Turbopack, were not affected by the breach. However, Vercel has contacted customers whose application data and security keys may have been exposed, advising them to rotate credentials as a precaution.

Corporate Response And Immediate Guidelines

In a public update, Vercel CEO Guillermo Rauch urged customers to update all relevant keys and credentials used in deployments. Details about the attackers remain limited, although the threat actor has claimed links to the ShinyHunters group, known for previous breaches involving cloud and database services.

Broader Supply Chain Implications

The incident reflects a broader rise in supply chain attacks targeting widely used tools and integrations. Compromising a single application can provide access to multiple organizations, increasing the scale and impact of such breaches.

Context AI Breach Clarification

Context AI confirmed a separate security incident in March involving its Office Suite application. Initial disclosures suggested limited impact, but the company now indicates that compromised OAuth tokens may have affected a wider group of users. Investigation into the breach is ongoing, with several aspects, including attacker intent, still unclear.

Conclusion

The Vercel incident highlights risks associated with interconnected systems and third-party integrations. Companies are expected to reassess access controls and strengthen security practices to mitigate similar threats.

Eurobank Plans €1 Billion Investment In AI And Digital Banking By 2028

Eurobank plans to invest about €1 billion in technology from 2025 through 2028, its largest technology investment program to date. The Banking Forward strategy focuses on digital banking, artificial intelligence, customer experience and a “phygital” model combining digital services with face-to-face support.

Digital Banking Dominates Customer Activity

Digital channels already account for 96% of Eurobank transactions, with 61% completed through the Eurobank Mobile App. Among customers aged 35 and under, digital adoption reaches 94%.

Customers make about 574 million annual logins across e/m-banking and more than 1 million digital transactions each day. During the first half of 2026, one in three banking products was acquired digitally.

AI Moves Into Everyday Banking

Eurobank is expanding the use of AI through tools including EVA, its digital customer assistant, and myEVA, an AI-powered voice assistant for employees. The technology is also being applied to mortgage assessments, customer feedback analysis and contractual documents.

The bank’s technology architecture is built around five areas: digital channels, customer experience orchestration, data and AI, core banking, and infrastructure and cloud. About 50% of its applications and digital channels are already cloud-based.

Investment Extends Beyond Technology

The program is intended to reshape how Eurobank operates, combining automation and AI with employee development and human support. The bank says the approach is designed to improve services while maintaining access to face-to-face banking when customers need it.

Aretilaw firm
The Future Forbes Realty Global Properties
Uol
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter