Wednesday, 11 June 2025
30.3 C
Singapore
30.4 C
Thailand
27.5 C
Indonesia
28.9 C
Philippines

Security breach detected in Zapier’s code repositories

Zapier confirmed a security breach that exposed customer data after unauthorized access to its code repositories. Here's what you need to know.

Zapier, a popular platform that allows users to create automation across various apps and services, informed its customers on Friday about a security breach involving its code repositories. The company revealed that an “unauthorized user” had accessed specific code repositories and may have gained access to customer data. This was discovered after a detailed audit uncovered that customer data had been “inadvertently copied” to these repositories during debugging processes.

How the breach occurred

Zapier became aware of the breach on Thursday, February 27, 2025, after detecting unauthorized access to the affected repositories. According to an email sent to customers, the breach occurred due to a misconfiguration in an employee’s account’s two-factor authentication (2FA) settings. As a result, the hacker could gain access to the repositories.

Once the breach was detected, Zapier quickly secured the affected repositories, invalidating the unauthorized user’s access. The company assured customers that the breach did not affect its core systems, including databases, payment systems, or authentication processes.

The company emphasized that the code repositories, which typically should not contain customer data, had mistakenly stored some information. Although this incident was isolated, Zapier immediately investigated the issue and secured customer data. It was revealed that some customer information may have been accessed due to this error.

What you need to know and actions to take

Zapier’s team reviews internal processes to ensure such incidents do not happen again. While the company assured customers that the breach did not affect authentication tokens or payment systems, it advised users to take precautionary measures. Customers are encouraged to rotate any authentication tokens that might have been exposed and review the security settings of their Zapier account, especially by enabling 2FA where available.

Additionally, Zapier provided customers with a secure link to access any impacted data, allowing them to review the information and take necessary actions to safeguard their accounts. The company has pledged to continue its audit and improve security measures.

For further support or inquiries, Zapier customers should contact the company through the contact form or directly reply to the email sent regarding the incident.

Company response and future plans

Zapier’s Head of Security, Zeeshan Khadim, signed the email, reassuring customers that the company is taking all necessary steps to prevent future security breaches. A full audit of the company’s internal processes is underway, ensuring that similar issues do not affect users again. The company’s swift response demonstrates its commitment to securing customer data and reinforcing trust in its platform.

While this incident may have caused concern, Zapier’s transparency and quick actions should reassure its customers that the issue is being taken seriously and remedial steps are being taken.

Hot this week

Sony A7C II review: Compact power with full-frame performance

The Sony α7C II blends compact design with powerful autofocus, 33MP full-frame quality, and strong 4K video tools for hybrid creators.

YouTube’s creator economy in Southeast Asia powers rise of video commerce and brand trust

YouTube’s creator economy is transforming video commerce in Southeast Asia, creating opportunities for brands through trusted creator partnerships.

Gemini now lets you schedule AI tasks — here’s how it works

Google’s Gemini app now includes Scheduled Actions, letting users automate AI tasks and reminders within the Google ecosystem.

GoTo completes major cloud migration to Alibaba Cloud to support Indonesia’s digital finance future

GoTo Financial completes cloud migration to Alibaba Cloud in Jakarta, boosting scalability, efficiency and data sovereignty compliance.

SPP and Hitachi partner to deploy AI solution for US energy grid challenges

Hitachi, SPP, and NVIDIA partner to build AI-driven solution that speeds up US energy grid interconnections and boosts reliability.

Apple’s visionOS 26 brings spatial widgets, lifelike avatars, and shared experiences

Apple’s visionOS 26 update brings spatial widgets, improved avatars, and shared headset experiences for a more immersive digital world.

Apple’s next AirPods update could change how you record content

Apple’s new AirPods update promises studio-quality audio recording for creators using iPhones — no extra mic needed.

OpenAI says it now earns US$10 billion a year in revenue

OpenAI says its yearly revenue is now US$10B, doubling last year’s total, and its AI tools are used by over 500 million users and 3 million businesses.

Apple unveils macOS Tahoe with smarter tools and a new look

Apple reveals macOS Tahoe, which will be released this autumn and feature a fresh design, iPhone link upgrades, and smarter Spotlight tools.

Related Articles

Popular Categories