Skip to content

ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants

Cybersecuritynews Guru Baran April 27, 2026

A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Depot, Tenable, Mayo Clinic, and U.S. state government workers, through a hardcoded third-party API key that was first reported in January 2025 and remains unrotated as of April 2026. The […]