Switch language한국어
Back to the list

The $2 Million Permission You Forgot You Granted

TL;DR AI

Key summary

2 min read
  1. Attackers used a stolen OAuth token from a Context.ai employee infected with Lumma Stealer to move through trusted integrations into Vercel’s internal environment.

  2. The intrusion reportedly exposed internal environment variables and led to a $2 million ransom demand.

  3. The case highlights how one overbroad third-party login can bypass MFA and extend trust across connected cloud services.

  4. Entities tied to the incident include Vercel, Context.ai, Google Workspace, Drifts Salesforce integration, UNC6395, and Next.js.

Read the original