ClickUp Discloses Exposure of Customer Emails and API Token
ID: b276d969-5780-50c4-b75e-75a52f2b9775
STIX ID: report--b276d969-5780-50c4-b75e-75a52f2b9775
Feed Name: securityonline.info
Threat Score
ClickUp disclosed that a configuration oversight in client-side feature flag targeting (Split.io) exposed 893 customer email addresses and a single active workspace API token between October 7, 2025 and April 27, 2026; the company removed the emails, invalidated the token, and plans automated scanning to prevent PII/credential exposures. The issue was reported earlier but mishandled via triage and spam-filtering delays, and no confirmed malicious access was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
