Zapier Security Incident: Misconfigured 2FA Leads to Unauthorized Access
2025-03-01

Zapier experienced a security incident due to a misconfiguration in an employee's two-factor authentication (2FA). An unauthorized user gained access to certain code repositories. While no databases or production systems were affected, some customer data may have been inadvertently copied for debugging purposes. Zapier has secured the repositories, provided affected customers with a secure link to their data, and recommends reviewing and rotating any potentially compromised plain text authentication tokens. They also advise reviewing account security settings and activating 2FA where possible.
Tech
security incident