logo

Postman Workspaces Leak 30000 API Keys and Sensitive Tokens

ID: 82e8a372-c7d1-536a-a8e4-f0bf27dc9824

STIX ID: report--82e8a372-c7d1-536a-a8e4-f0bf27dc9824

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-12-24

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

CloudSEK’s year-long investigation found more than 30,000 public Postman workspaces leaking sensitive data—API keys, access/refresh tokens, and admin credentials—affecting organizations across sectors and exposing services such as GitHub, Slack, and Salesforce; causes include misconfigured access, plaintext secrets, and accidental public sharing, and recommended mitigations are environment variables, token rotation, and dedicated secret-management tools while Postman has begun enforcing secret-protection policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.