- Zapier sends a letter with data violation to affected customers
- It says a threat actor a 2FA -forced configuration to violate an account
- They gained access to some sensitive customer information
Popular Automation Tool Zapier has suffered a cyberattack that saw the company losing sensitive customer information.
News about the attack was reported by The VergeA copy of the letter about violation of the message, the company’s head of security, Zeeshan Khadim, was sent to affected customers.
According to the letter, a named threat actor abused a “two-factor approval (2FA) misunderstanding” in an employee’s account to gain unauthorized access to certain Zapier Code stocks. “
Training AI
Normally, this would not affect our customers, ”says the letter further, but after revision of the content of the depots, Zapier found some customer information that was” inadvertently copied to the depots for mistake purposes “.
These were “isolated events,” the security manager said. We do not know exactly how many people were affected or what kind of information was stolen. However, we know what was not: “This incident affected any Zapier database, infrastructure or production, approval or payment systems.”
When Zapier was aware of the incident, it ensured access to the depots and invalid the compromised report. The company also generated a secure link that affected customers can see a copy of their affected data.
“Review this data and take appropriate actions that may include rotating any valid ordinary text approval tokens that may have been used in places such as code or webhook -step configuration found in the affected data,” the letter further states, which suggests what information may have been taken. “Note that your ZAP/APP approval tooken were not affected by this incident. We also recommend that you review security settings in your Zapier account and your other online apps, including activating 2FA where available. “
The company is now running a thorough audit and internal process remedy to prevent similar incidents from happening in the future as well.