← Vanta

2025 Product bug — customer data cross-exposure

2025 Unknown records affected Share on X

Data compromised

Employee names, roles, MFA configuration

Technical writeup

A code change intended to improve API performance inadvertently removed a domain ID filter. Data from one customer's third-party integrations was exposed to other Vanta customers. Fewer than 4% of customers affected. Exposed data included employee names, roles, and configuration info such as MFA settings. No API keys, credentials, or intrusion. Bug reverted May 27, remediation completed June 3.

Root cause

Product bug; missing domain ID filter in API.

References