HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

ClickUp API Key Leak Exposes Hundreds of Enterprise Emails Over a Year

A hard‑coded ClickUp API key was publicly exposed, allowing unrestricted retrieval of corporate and government email addresses for more than twelve months. The breach highlights the need for strict secret‑management and third‑party risk controls when using SaaS collaboration tools.

LiveThreat™ Intelligence · 📅 April 29, 2026· 📰 techrepublic.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
techrepublic.com

ClickUp API Key Leak Exposes Hundreds of Enterprise Emails Over a Year

What Happened — A hard‑coded ClickUp API key was discovered in a public repository, allowing anyone to query the ClickUp API and retrieve email addresses of hundreds of corporate and government users for more than twelve months.

Why It Matters for TPRM

  • SaaS providers can unintentionally expose sensitive data through insecure code practices.
  • Third‑party email addresses are often used for phishing and credential‑stuffing campaigns against client organizations.
  • Long‑standing exposure increases the risk of downstream breaches in downstream supply‑chain relationships.

Who Is Affected — Enterprises across multiple sectors (technology, finance, government) that use ClickUp for project management and collaboration.

Recommended Actions

  • Review all integrations with ClickUp and verify that API keys are rotated and stored securely.
  • Conduct a focused email‑address inventory to identify any exposed addresses and enforce MFA.
  • Update vendor risk assessments to include secure‑coding and secret‑management controls for SaaS providers.

Technical Notes — The leak stemmed from a hard‑coded API token (no authentication rotation) that granted read‑only access to the /users endpoint, leaking email addresses. No CVE is associated; the issue is a misconfiguration/secret‑management failure. Source: TechRepublic Security

📰 Original Source
https://www.techrepublic.com/article/news-clickup-api-key-email-exposure/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.