Postman Data Leaks: The Hidden Risks Lurking in Your Workspaces
ID: 8bbefa77-a489-5e5b-9163-da19c4d3b4cc
STIX ID: report--8bbefa77-a489-5e5b-9163-da19c4d3b4cc
Feed Name: CloudSEK Blog
Threat Score
CloudSEK's TRIAD team reports that over 30,000 publicly accessible Postman workspaces exposed sensitive information—API keys, tokens, credentials, and PII—across many services (Okta, Zendesk, Razorpay, New Relic, GitHub, Slack, etc.), demonstrating how misconfigured sharing, plaintext storage, and long-lived tokens can enable data breaches, unauthorized access, and financial fraud; the report includes case studies, a reproduced New Relic POC, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
