Your AI vendor's security team probably passed every question on your due diligence checklist. That was never the part of the relationship most likely to hurt you. Two breaches this year, one at Vercel and Context.ai, one at Salesloft and Drift, both moved through a chain of connected tools nobody was tracking. The vendor you approved was not the weak link. The tool your vendor quietly connected to was.
The real AI attack surface is not the vendor you signed a contract with. It is the chain of plugins, browser extensions, and connected agents that vendor links to after signing, each carrying access tokens your legal team never reviewed. Recent breaches at Vercel and Salesloft show attackers reaching customer data through integrations the customer never knew existed.
In February 2026, a Context.ai employee's machine was infected with credential-stealing malware, exposing a corporate Google Workspace login. A Vercel employee had separately signed into Context.ai's browser extension using their own enterprise Google account, and the attacker rode that connection into Vercel's internal systems. Vercel confirmed a limited subset of customers had credentials exposed, and a threat actor later offered the stolen data for sale, according to reporting from The Hacker News.
Vercel and Context.ai's customers had no direct relationship with each other. The exposure moved through an OAuth grant that sat outside both companies' formal vendor review, invisible to anyone but the two engineering teams that set it up.
For Vercel's customers, the practical fallout was days of uncertainty about which environment variables and credentials had actually been touched, followed by mandatory credential rotation across affected deployments. That is lost engineering time, delayed releases, and a support queue full of customers asking questions your own team cannot fully answer yet because the vendor is still investigating.
Salesloft's Drift chatbot held OAuth tokens that let it act inside customer Salesforce and Google Workspace accounts on their behalf. When attackers stole those tokens in August 2025, they did not need to breach each of the roughly 700 affected organizations one at a time, they authenticated as Drift and walked into whatever systems Drift had permission to reach.
FINRA's cybersecurity alert on the incident instructed member firms to disconnect the integration, rotate credentials, and audit access logs, because some victims lost API keys, cloud credentials, and tokens embedded in support cases, not just contact records. Put the two breaches side by side and the shape is identical. Access was granted broadly and permanently for one narrow purpose, nobody set an expiration on it, and an attacker who found the connection rode it into every account it touched.
For the financial services firms on FINRA's list, the fallout carried more than a cleanup cost. Firms had to work out whether the exposed data triggered breach notification duties under state law and their own regulatory disclosure requirements, on a timeline set by the incident rather than their compliance calendar. A vendor risk failure inside a chatbot integration became a regulatory filing question at multiple firms within days of the disclosure.
Most vendor risk programs review the vendor you are signing with. They rarely review what that vendor connects to six months later. CISA's guidance on information and communications technology supply chain risk management tells organizations to map their suppliers' sources, not just their suppliers, because risk moves through tiers a standard security questionnaire never reaches. NIST's cybersecurity supply chain risk management framework makes the same point with more structure, treating a vendor's subcontractors and integration partners as part of the risk boundary you are responsible for managing rather than a separate company's problem.
This is not a theoretical gap. Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled year over year to 30 percent. AI integrations are pushing that number higher, because every new plugin, browser extension, or connected agent is another party your data now touches without a formal review ever happening.
The Vercel breach did not start with a procurement decision. It started with an employee installing a browser extension to get more out of an AI tool, using a real corporate login because that was the fastest way in. That pattern repeats across most businesses now. Employees connect AI writing assistants, meeting transcription tools, and coding copilots to work accounts because the productivity gain is immediate and the integration takes thirty seconds to approve.
Nobody in IT signs off on that OAuth grant, because nobody in IT knew the extension existed. Each of those grants is a fourth party your formal vendor list does not include. You may have carefully reviewed the AI platform your business pays for. You almost certainly have not reviewed every extension, plugin, and connected app your employees granted access to on top of it, and neither did the vendor whose name is on your contract.
| What Standard Contracts Cover | What They Leave Out |
|---|---|
| Data handling and confidentiality terms at signing | Disclosure when a new subprocessor or integration gains access later |
| Breach notification for incidents at the vendor itself | Notification timelines for incidents at a connected fourth party |
| A one-time subprocessor list reviewed at onboarding | Token lifecycle terms covering scope, expiration, and revocation |
| Audit rights over the vendor's own environment | Audit rights that extend to the vendor's material subprocessors |
Read that table as a checklist against your own contracts, not as an abstract comparison. Every item on the right came from a scenario that already happened to real companies this year, and each gap is the reason those companies found out about their exposure from a researcher's writeup or a forum post instead of from their own vendor.
Ask for four things before you renew or sign anything new: ongoing subprocessor disclosure, token lifecycle limits, fourth-party breach notification timelines, and audit rights that reach past the vendor's own walls. None of these are unusual asks. They are the direct answer to what happened at Vercel and at Salesloft: access that outlived its purpose, held by a party nobody evaluated, discovered only after the damage was done.
If your current contracts stop at the top row of that table, you are not alone. Most agreements signed before 2024 never anticipated a chatbot with its own OAuth grant. Securafy's AI governance work starts by mapping exactly which tools your AI vendors are connected to and rewriting contract language around what those connections can actually do, not just running through a security questionnaire once and filing it away.
Before you sign the next AI vendor, run the decision through a documented framework instead of a sales call and a gut check. Securafy's Cybersecurity Buyer's Guide walks through the questions that separate a vendor with real subprocessor discipline from one that just says the right things in a pitch.
If your business operates under HIPAA, GLBA, CMMC, or a similar framework, a fourth-party breach does not excuse you from your own reporting duties. Most breach notification laws measure the clock from when you knew or should have known about an exposure of covered data, not from when your direct vendor got around to telling you. If your AI vendor's own vendor gets breached and neither one tells you for weeks, that delay becomes your compliance problem the moment a regulator or an auditor asks why you did not know sooner.
Cyber insurance gets complicated here too. Underwriters increasingly ask about subprocessor visibility and vendor contract language at renewal, and a policy application that assumes you can name your material data processors will not hold up against a gap you cannot document. A fourth-party breach you cannot explain to your carrier turns into a claim dispute on top of the breach itself, at the exact moment you need the payout to move fast.
Start with every AI vendor you already use. Ask for a current subprocessor list and a plain description of how integration tokens get scoped and revoked. A vendor that answers within a day is telling you something useful. A vendor that stalls is telling you something too.
This matters more for smaller organizations, not less. CISA's supply chain guidance for small and medium-sized businesses points out that SMBs often lack the staff to track vendor subprocessor changes as they happen, which is exactly why attackers increasingly use smaller companies as the path into larger targets further up the chain.
Neither of these breaches involved a novel exploit. Both involved ordinary integrations that nobody was required to disclose, monitor, or revoke on a reasonable timeline. Governance here is less about picking the right AI tool and more about knowing, and controlling, everything that tool is allowed to talk to.
Closing the fourth-party gap starts with treating AI vendor risk as something your team reviews on an ongoing basis, not a box you check once at signing. That takes people who know what to ask, not another dashboard to watch.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.