ClickUp left a hardcoded third-party API key in a publicly accessible JavaScript file on its homepage, exposing 959 email addresses and 3,165 internal feature flags through unauthenticated requests. Reports said the issue was disclosed through HackerOne on January 17, 2025, yet the key allegedly remained active and unrotated into late April 2026. The exposed email addresses reportedly belonged to staff at major enterprises including Fortinet, Home Depot, Autodesk, Tenable, Rakuten, Mayo Clinic, Permira, and Akin Gump, as well as government personnel in multiple U.S. states, Queensland, and New Zealand.
Researchers said no credentials, bypass, or advanced tooling were needed to retrieve the data because the key was embedded in client-side code loaded before authentication. In addition to personal contact information, the leaked feature flags revealed internal product testing, beta features, A/B experiments, and possible roadmap details, creating risks that include targeted phishing, social engineering, credential-stuffing attempts, competitive intelligence collection, and potential platform abuse. ClickUp had not publicly acknowledged the exposure at the time of reporting.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned confirmed the Pitney Bowes breach and said the leaked dataset contained 8.2 million unique email addresses, plus names, phone numbers, physical addresses, and some employee job-title records. This public confirmation established the scale and data types exposed in the incident.
The exposed ClickUp API key remained active and unrotated through late April 2026, continuing to expose 959 email addresses and 3,165 internal feature flags without authentication. Reports said ClickUp had not publicly acknowledged the issue at the time of publication.
In April 2026, ShinyHunters claimed to have obtained Pitney Bowes data as part of a broader pay-or-leak extortion campaign targeting multiple organizations. According to the reports, negotiations allegedly failed and the group then publicly released the stolen data.
A researcher disclosed to ClickUp via HackerOne that a hardcoded third-party API key in a publicly accessible JavaScript file allowed unauthenticated access to sensitive backend data. The issue was reportedly submitted on January 17, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcehaveibeenpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.