2025 Product bug — customer data cross-exposure
Data compromised
Employee names, roles, MFA configuration
Technical writeup
A code change intended to improve API performance inadvertently removed a domain ID filter. Data from one customer's third-party integrations was exposed to other Vanta customers. Fewer than 4% of customers affected. Exposed data included employee names, roles, and configuration info such as MFA settings. No API keys, credentials, or intrusion. Bug reverted May 27, remediation completed June 3.
Root cause
Product bug; missing domain ID filter in API.