Companies get attacked through all kinds of doors — but usually you picture a sketchy email or a guessed password. This time the door was something quieter: a single employee's AI helper. A company called Vercel — which runs the behind-the-scenes plumbing for thousands of websites and apps — got broken into because one worker had connected a third-party AI tool to their account. Crooks compromised that tool, used it to take over the worker's email, and from there walked straight into the company's most sensitive systems.
Why it matters: it took just one person and one AI add-on. Most companies have no idea what AI tools their employees are plugging in or what those tools can quietly reach.
So how does it touch you? Every AI helper someone connects to a work account is a fresh door into the building — and behind Vercel's door sat the keys to thousands of other companies' websites and apps, the kind you and I use every day. You can do everything right with your own passwords and still be exposed because a stranger you'll never meet connected the wrong tool. The more of these helpers get plugged in, the more doors there are — and nobody's counting them.
