- VANTA admits it introduced an error in its code
- The error resulted in a small subgroup of customers having data exposed
- The error is corrected and the affected customers are notified
Security and Compliance – Automatization Company Vanta has confirmed to share sensitive customer data with other customers by mistake.
In a statement (via Techcrunch) that the company said that a change it had made in the code resulted in a security breach. In it, some sensitive data from a small subgroup of customers were shared with other customers.
The incident was discovered on May 26, and the remedy efforts are currently undergoing the process to end before June 4.
Hundreds of victims
As a result of the incident, “a subgroup of data from fewer than 20% of our third-party integrations” was exposed to other Vanta customers, the company’s Chief Product Officer Jeremy Epling said.
He added that fewer than 4% of Vanta customers have been affected and they have already been notified.
As the company has more than 10,000 customers, it would set the violation of up to 400. At the same time, data on data violation VANTA says that the data typically includes employee names, roles and information on various tools, such as 2FA. The company did not confirm exactly what type of data was grabbed.
VANTA is a security and compliance automation platform that helps companies achieve and maintain certifications such as SOC 2, ISO 27001, HIPAA and GDPR more effectively through continuous monitoring and integration.
Among its customers is Atlassian, Omni Hotels, Quora and Zoominfo.