Skip to content
Securafy AI Lab by Securafy
AI Security & Governance

The Real AI Attack Surface Is Your Vendor's Vendor

Your AI vendor's security team probably passed every question on your due diligence checklist. That was never the part of the relationship most likely to hurt you. Two breaches this year, one at Vercel and Context.ai, one at Salesloft and Drift, both moved through a chain of connected tools nobody was tracking. The vendor you approved was not the weak link. The tool your vendor quietly connected to was.

In this article

Your AI vendor's security team probably passed every question on your due diligence checklist. That was never the part of the relationship most likely to hurt you. Two breaches this year, one at Vercel and Context.ai, one at Salesloft and Drift, both moved through a chain of connected tools nobody was tracking. The vendor you approved was not the weak link. The tool your vendor quietly connected to was.

The real AI attack surface is not the vendor you signed a contract with. It is the chain of plugins, browser extensions, and connected agents that vendor links to after signing, each carrying access tokens your legal team never reviewed. Recent breaches at Vercel and Salesloft show attackers reaching customer data through integrations the customer never knew existed.

What Actually Broke During the Vercel and Context.ai Breach?

In February 2026, a Context.ai employee's machine was infected with credential-stealing malware, exposing a corporate Google Workspace login. A Vercel employee had separately signed into Context.ai's browser extension using their own enterprise Google account, and the attacker rode that connection into Vercel's internal systems. Vercel confirmed a limited subset of customers had credentials exposed, and a threat actor later offered the stolen data for sale, according to reporting from The Hacker News.

Vercel and Context.ai's customers had no direct relationship with each other. The exposure moved through an OAuth grant that sat outside both companies' formal vendor review, invisible to anyone but the two engineering teams that set it up.

For Vercel's customers, the practical fallout was days of uncertainty about which environment variables and credentials had actually been touched, followed by mandatory credential rotation across affected deployments. That is lost engineering time, delayed releases, and a support queue full of customers asking questions your own team cannot fully answer yet because the vendor is still investigating.

Why Did One Compromised Integration Take Down 700 Companies?

Salesloft's Drift chatbot held OAuth tokens that let it act inside customer Salesforce and Google Workspace accounts on their behalf. When attackers stole those tokens in August 2025, they did not need to breach each of the roughly 700 affected organizations one at a time, they authenticated as Drift and walked into whatever systems Drift had permission to reach.

FINRA's cybersecurity alert on the incident instructed member firms to disconnect the integration, rotate credentials, and audit access logs, because some victims lost API keys, cloud credentials, and tokens embedded in support cases, not just contact records. Put the two breaches side by side and the shape is identical. Access was granted broadly and permanently for one narrow purpose, nobody set an expiration on it, and an attacker who found the connection rode it into every account it touched.

For the financial services firms on FINRA's list, the fallout carried more than a cleanup cost. Firms had to work out whether the exposed data triggered breach notification duties under state law and their own regulatory disclosure requirements, on a timeline set by the incident rather than their compliance calendar. A vendor risk failure inside a chatbot integration became a regulatory filing question at multiple firms within days of the disclosure.

The Fourth-Party Blind Spot in Vendor Risk Programs

Most vendor risk programs review the vendor you are signing with. They rarely review what that vendor connects to six months later. CISA's guidance on information and communications technology supply chain risk management tells organizations to map their suppliers' sources, not just their suppliers, because risk moves through tiers a standard security questionnaire never reaches. NIST's cybersecurity supply chain risk management framework makes the same point with more structure, treating a vendor's subcontractors and integration partners as part of the risk boundary you are responsible for managing rather than a separate company's problem.

This is not a theoretical gap. Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled year over year to 30 percent. AI integrations are pushing that number higher, because every new plugin, browser extension, or connected agent is another party your data now touches without a formal review ever happening.

How Shadow AI Integrations Multiply the Exposure

The Vercel breach did not start with a procurement decision. It started with an employee installing a browser extension to get more out of an AI tool, using a real corporate login because that was the fastest way in. That pattern repeats across most businesses now. Employees connect AI writing assistants, meeting transcription tools, and coding copilots to work accounts because the productivity gain is immediate and the integration takes thirty seconds to approve.

Nobody in IT signs off on that OAuth grant, because nobody in IT knew the extension existed. Each of those grants is a fourth party your formal vendor list does not include. You may have carefully reviewed the AI platform your business pays for. You almost certainly have not reviewed every extension, plugin, and connected app your employees granted access to on top of it, and neither did the vendor whose name is on your contract.

Where Most AI Vendor Contracts Fall Short

What Standard Contracts Cover What They Leave Out
Data handling and confidentiality terms at signing Disclosure when a new subprocessor or integration gains access later
Breach notification for incidents at the vendor itself Notification timelines for incidents at a connected fourth party
A one-time subprocessor list reviewed at onboarding Token lifecycle terms covering scope, expiration, and revocation
Audit rights over the vendor's own environment Audit rights that extend to the vendor's material subprocessors

Read that table as a checklist against your own contracts, not as an abstract comparison. Every item on the right came from a scenario that already happened to real companies this year, and each gap is the reason those companies found out about their exposure from a researcher's writeup or a forum post instead of from their own vendor.

What Should You Actually Demand in AI Vendor Contracts?

Ask for four things before you renew or sign anything new: ongoing subprocessor disclosure, token lifecycle limits, fourth-party breach notification timelines, and audit rights that reach past the vendor's own walls. None of these are unusual asks. They are the direct answer to what happened at Vercel and at Salesloft: access that outlived its purpose, held by a party nobody evaluated, discovered only after the damage was done.

  • Disclosure requirements for any new subprocessor or integration that gains access to your data, updated on a rolling basis instead of reviewed once a year
  • Token lifecycle terms that define scope, expiration, and revocation timelines, so a login granted for one integration cannot quietly retain broader access
  • Breach notification clauses that specifically cover incidents at a vendor's connected tools, not only incidents at the vendor itself
  • Audit rights that extend to a vendor's material subprocessors, not just the vendor's own environment

If your current contracts stop at the top row of that table, you are not alone. Most agreements signed before 2024 never anticipated a chatbot with its own OAuth grant. Securafy's AI governance work starts by mapping exactly which tools your AI vendors are connected to and rewriting contract language around what those connections can actually do, not just running through a security questionnaire once and filing it away.

Before you sign the next AI vendor, run the decision through a documented framework instead of a sales call and a gut check. Securafy's Cybersecurity Buyer's Guide walks through the questions that separate a vendor with real subprocessor discipline from one that just says the right things in a pitch.

What Does This Mean for Your Compliance Obligations?

If your business operates under HIPAA, GLBA, CMMC, or a similar framework, a fourth-party breach does not excuse you from your own reporting duties. Most breach notification laws measure the clock from when you knew or should have known about an exposure of covered data, not from when your direct vendor got around to telling you. If your AI vendor's own vendor gets breached and neither one tells you for weeks, that delay becomes your compliance problem the moment a regulator or an auditor asks why you did not know sooner.

Cyber insurance gets complicated here too. Underwriters increasingly ask about subprocessor visibility and vendor contract language at renewal, and a policy application that assumes you can name your material data processors will not hold up against a gap you cannot document. A fourth-party breach you cannot explain to your carrier turns into a claim dispute on top of the breach itself, at the exact moment you need the payout to move fast.

The Questions To Ask Before Your Next Renewal

Start with every AI vendor you already use. Ask for a current subprocessor list and a plain description of how integration tokens get scoped and revoked. A vendor that answers within a day is telling you something useful. A vendor that stalls is telling you something too.

This matters more for smaller organizations, not less. CISA's supply chain guidance for small and medium-sized businesses points out that SMBs often lack the staff to track vendor subprocessor changes as they happen, which is exactly why attackers increasingly use smaller companies as the path into larger targets further up the chain.

  • Request a current subprocessor and integration list from every AI vendor with access to your data
  • Compare each vendor contract against the four clauses above and flag the gaps before renewal, not after an incident
  • Run your own environment through a cybersecurity assessment to see which logins and browser extensions on your team already carry access nobody has reviewed

Neither of these breaches involved a novel exploit. Both involved ordinary integrations that nobody was required to disclose, monitor, or revoke on a reasonable timeline. Governance here is less about picking the right AI tool and more about knowing, and controlling, everything that tool is allowed to talk to.

Where To Go From Here

Closing the fourth-party gap starts with treating AI vendor risk as something your team reviews on an ongoing basis, not a box you check once at signing. That takes people who know what to ask, not another dashboard to watch.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.

Ric Hall
Ric Hall

Ric Hall is the Chief Revenue Officer at Securafy, with decades of experience in enterprise infrastructure, cloud technology, sales leadership, and business strategy.

He writes for leaders trying to make sense of big technology decisions without getting trapped in vague promises or polished sales language. His articles cover provider selection, IT budgeting, co-managed services, cybersecurity investments, modernization, and the questions businesses should ask before signing a contract.

Ric’s strength is connecting technical decisions to business outcomes, helping leaders understand not just what they are buying, but why it matters and whether it will still make sense 3 years from now.

Writes about: IT budgeting, provider evaluation, cybersecurity ROI, co-managed IT, cloud modernization, vendor selection, technology strategy

More from Ric Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.