← Zapier

2025 Zapier — unauthorized access to internal code repositories; 2FA misconfiguration; tokens in repo history

2025 Unknown records affected Share on X

Data compromised

Repository-resident debugging artifacts including API/auth tokens for a bounded customer set per Zapier customer communications summarized in press

Technical writeup

Zapier disclosed late February 2025 activity in which an adversary used stolen employee credentials against source-control systems after a two-factor authentication misconfiguration reportedly left a workforce account reachable without full MFA enforcement. Vendor and trade coverage emphasized that core production databases were not breached but that some customer-touching secrets—including authentication tokens that staff had copied into repositories for troubleshooting—could have been read from Git history, prompting credential rotation guidance for affected integrations.

Root cause

Account takeover path enabled by MFA configuration gap on an employee identity; follow-on access to hosted code repositories

References