Vercel was breached through a compromised Google Workspace OAuth app from a third-party AI tool, potentially affecting hundreds of organizations.
Vercel confirmed it was hacked via a third-party AI tool's Google Workspace OAuth app that was compromised in a broader attack. The breach is not isolated — the same OAuth app potentially affected hundreds of users across many organizations. Vercel published indicators of compromise (IOCs) to help the wider community investigate. Google Workspace admins are being urged to audit connected OAuth apps immediately.
This is a supply-chain OAuth attack: a third-party AI tool's app was compromised, and any org that granted it Google Workspace access is potentially exposed. This isn't a Vercel-specific flaw — it's a class of vulnerability that affects any team using AI tools integrated via Google OAuth. Hundreds of orgs are in scope. Vercel published IOCs; pull them and cross-reference your environment today.
Pull your Google Workspace OAuth app list via the Admin SDK this week and flag any AI tools granted sensitive scopes (gmail.readonly, drive, admin.directory) — revoke anything non-essential before you know you're clean.
Go to admin.google.com → Security → Access and data control → API controls → Manage third-party app access
Tags