Sunday, 2 March 2025
25.8 C
Singapore
29 C
Thailand
20.8 C
Indonesia
26.5 C
Philippines

Security breach detected in Zapier’s code repositories

Zapier confirmed a security breach that exposed customer data after unauthorized access to its code repositories. Here's what you need to know.

Zapier, a popular platform that allows users to create automation across various apps and services, informed its customers on Friday about a security breach involving its code repositories. The company revealed that an โ€œunauthorized userโ€ had accessed specific code repositories and may have gained access to customer data. This was discovered after a detailed audit uncovered that customer data had been โ€œinadvertently copiedโ€ to these repositories during debugging processes.

How the breach occurred

Zapier became aware of the breach on Thursday, February 27, 2025, after detecting unauthorized access to the affected repositories. According to an email sent to customers, the breach occurred due to a misconfiguration in an employee’s account’s two-factor authentication (2FA) settings. As a result, the hacker could gain access to the repositories.

Once the breach was detected, Zapier quickly secured the affected repositories, invalidating the unauthorized user’s access. The company assured customers that the breach did not affect its core systems, including databases, payment systems, or authentication processes.

The company emphasized that the code repositories, which typically should not contain customer data, had mistakenly stored some information. Although this incident was isolated, Zapier immediately investigated the issue and secured customer data. It was revealed that some customer information may have been accessed due to this error.

What you need to know and actions to take

Zapier’s team reviews internal processes to ensure such incidents do not happen again. While the company assured customers that the breach did not affect authentication tokens or payment systems, it advised users to take precautionary measures. Customers are encouraged to rotate any authentication tokens that might have been exposed and review the security settings of their Zapier account, especially by enabling 2FA where available.

Additionally, Zapier provided customers with a secure link to access any impacted data, allowing them to review the information and take necessary actions to safeguard their accounts. The company has pledged to continue its audit and improve security measures.

For further support or inquiries, Zapier customers should contact the company through the contact form or directly reply to the email sent regarding the incident.

Company response and future plans

Zapier’s Head of Security, Zeeshan Khadim, signed the email, reassuring customers that the company is taking all necessary steps to prevent future security breaches. A full audit of the companyโ€™s internal processes is underway, ensuring that similar issues do not affect users again. The companyโ€™s swift response demonstrates its commitment to securing customer data and reinforcing trust in its platform.

While this incident may have caused concern, Zapierโ€™s transparency and quick actions should reassure its customers that the issue is being taken seriously and remedial steps are being taken.

Hot this week

Susan Kare unveils new collection of Mac-inspired icons

Apple designer Susan Kare, in collaboration with Asprey Studio, unveils 32 new Mac-inspired physical icons in the limited-edition Esc Keys collection.

Mobile Legends: Bang Bang added to 2026 Asian Games as esports lineup expands

Mobile Legends: Bang Bang will be a medalled event at the 2026 Asian Games, joining a growing esports lineup at the international competition.

White House names Amy Gleason as DOGEโ€™s acting administrator

The White House confirms Amy Gleason as DOGEโ€™s acting administrator, not Elon Musk, amid growing concerns over Muskโ€™s role in government operations.

Appleโ€™s visionOS 2.4 update enhances Vision Pro with AI, Spatial Gallery, and more

Appleโ€™s visionOS 2.4 update for Vision Pro arrives in April, bringing Apple Intelligence, Spatial Gallery, a companion iPhone app, and improved Guest mode.

AI chatbot Grok briefly restricted results on Musk and Trump

Grok, Elon Muskโ€™s AI chatbot, briefly blocked results claiming Musk and Trump spread misinformation due to an unauthorised system update.

Mozilla updates Firefox terms after criticism over data handling

After criticism, Mozilla revises Firefoxโ€™s Terms of Use, clarifying data rights and addressing concerns about data-sharing practices.

Singaporeโ€™s sleep crisis: Women struggle the most

A sleep crisis is gripping Singapore, with stress and financial worries affecting sleep. Women struggle the most, impacting health, work, and relationships.

Mistral AI: The French startup challenging OpenAI

Learn about Mistral AI, the French AI startup rivalling OpenAI, its models, revenue strategy, and key partnerships, including Microsoft and AFP.

How OpenAI is shaping the future with its startup investments

OpenAIโ€™s Startup Fund has backed multiple AI-driven startups across industries, raising millions to support innovation in robotics, healthcare, and more.

Related Articles