Security incidents in task management tools.

Dated, source-linked records of publicly documented security events affecting popular task and project management products. Each record is visibly classified so a data exposure, API scrape, credential-stuffing attack, supply-chain compromise, and software vulnerability are not presented as interchangeable events.

Research and HIBP index check performed

The short answer

The library covers data exposures at ClickUp and Asana, each scoped to what the companies’ disclosures establish. [1][2]

It separately classifies Trello’s API-scraped profile dataset and monday.com’s downstream impact from the Codecov supply-chain compromise. [3][4]

The remaining records cover credential stuffing against Basecamp accounts and selected exploited vulnerabilities in self-hosted Jira and Confluence. [7][5][6]

Have I Been Pwned coverage is shown separately because absence from HIBP does not mean a vendor has no documented incident. [8]

Documented records.

01

Data exposure

ClickUp’s 2026 feature-flag data exposure.

ClickUp exposed 893 customer emails and one API token through client-readable feature flags in April 2026. See the timeline, scope, response, and sources.

Last fact-checked · 3 cited sources

Read the ClickUp record

02

Data exposure

Asana’s 2025 MCP data exposure.

Asana disclosed a 2025 MCP implementation flaw that could expose some customer data across organizations. Source-linked timeline, scope, response, and caveats.

Last fact-checked · 4 cited sources

Read the Asana record

03

API scrape

Trello data breach and incident history.

How an unauthenticated API linked 15.1 million Trello emails to names and usernames in 2024, with Atlassian’s response, timeline, and primary sources.

Last fact-checked · 10 cited sources

Read the Trello record

04

Supply-chain compromise

monday.com’s 2021 Codecov supply-chain incident.

monday.com disclosed read-only source-code access through the 2021 Codecov compromise, with the affected data, response, timeline, and primary sources.

Last fact-checked · 5 cited sources

Read the monday.com record

05

Vulnerability

Selected Atlassian Jira & Confluence vulnerability history.

A sourced history of exploited Jira and Confluence Server and Data Center vulnerabilities, including CISA KEV entries and Atlassian security advisories.

Last fact-checked · 16 cited sources

Read the Atlassian (Jira & Confluence) record

06

Credential stuffing

Basecamp security incident history.

Basecamp documented 30,000 login attempts and 124 successful account logins in 2019, while reporting no content access or compromise of its systems.

Last fact-checked · 4 cited sources

Read the Basecamp (37signals) record

How the records are classified

Classification describes the mechanism documented by the sources. It is not a severity score, and it prevents a vulnerability or account attack from being mislabeled as a vendor data breach.

Breach

Unauthorized access to or exfiltration from systems or data stores.

Data exposure

Data became accessible to unintended people because of a bug or configuration error.

API scrape

An API or public resource was queried at scale without a confirmed system intrusion.

Credential stuffing

Credentials stolen elsewhere were replayed against user accounts.

Supply-chain compromise

A third-party tool or dependency was compromised and used to reach the vendor.

Vulnerability

A disclosed software weakness; a vulnerability alone is not evidence of a vendor data breach.

Have I Been Pwned coverage

This table says only whether a product-attributed entry was located in the live HIBP index on July 13, 2026. It does not label any vendor incident-free, and it is intentionally separate from the source-backed records above. [8]

Source: Have I Been Pwned breached-sites index.

Vendor HIBP status (checked July 13, 2026) Scope note
Trello Listed Verified HIBP entry for the January 2024 API-scraped profile dataset.
ClickUp No product-attributed entry located The separate 2026 feature-flag data-exposure record is not represented in HIBP.
Asana No product-attributed entry located The separate 2025 MCP cross-customer exposure record is not represented in HIBP.
monday.com No product-attributed entry located The separate 2021 Codecov supply-chain record is not represented in HIBP.
Atlassian No product-attributed entry located Trello has its own HIBP entry; this row refers to Atlassian as the attributed breached entity.
Basecamp (37signals) No product-attributed entry located The 2019 account attack reused credentials likely obtained from breaches of other services.
Todoist (Doist) No product-attributed entry located HIBP status only; this is not a claim of incident-free history.
TickTick No product-attributed entry located HIBP status only; this is not a claim of incident-free history.
Any.do No product-attributed entry located HIBP status only; this is not a claim of incident-free history.
Microsoft To Do No product-attributed entry located Scoped to Microsoft To Do itself; Microsoft-wide corporate incidents are outside this product-level check.
Notion No product-attributed entry located HIBP status only; vulnerabilities and privacy reports require separate classification and evidence.
Wrike No product-attributed entry located HIBP status only; this is not a claim of incident-free history.
Airtable No product-attributed entry located HIBP status only; this is not a claim of incident-free history.

How these records are built

Every material statement is traced to a named source. The records prioritize vendor statements and advisories, securities filings, regulator publications, Have I Been Pwned records, NVD entries, and CISA’s Known Exploited Vulnerabilities catalog; contemporaneous reporting from established security press supplies details that primary material does not publish. Each page carries inline numbered citations and a dated source list.

Unverified claims do not establish facts and are excluded unless they are material to understanding a documented event and can be attributed precisely to a named source. Any included threat-actor claim remains explicitly labeled as unconfirmed and is never presented as a vendor-confirmed fact. Where a vendor disputes how an incident is labeled, both the dispute and the underlying facts appear.

The Have I Been Pwned table reports HIBP coverage only and was checked against the live breached-sites index on July 13, 2026. Absence of an HIBP entry is not evidence of a clean history: ClickUp, Asana, monday.com, Basecamp, and the Atlassian vulnerability record on this page all demonstrate event classes HIBP does not necessarily represent.

Corrections: if any claim on these pages is inaccurate or has been superseded, email hello@sealtask.com with a source and we will review and correct it.

Hub sources

Primary references for claims made directly on this collection page. Each detailed record carries its own complete, claim-level source list.

  1. 01
    ClickUp: April 27 feature-flag configuration disclosure - Primary vendor disclosure for the 2026 feature-flag data exposure
  2. 02
    Asana Form 10-Q for the quarter ended July 31, 2025 - Primary company filing for the 2025 MCP implementation flaw
  3. 03
    Have I Been Pwned: Trello breach entry - Verified record for the January 2024 API-scraped profile dataset
  4. 04
    monday.com Form F-1 filed May 17, 2021 - Primary company filing for monday.com’s Codecov supply-chain impact
  5. 05
    Atlassian security advisories and bulletins index - Primary vendor index for Jira and Confluence vulnerability records
  6. 06
    CISA Known Exploited Vulnerabilities catalog - Government catalog used to verify exploitation of selected Atlassian CVEs
  7. 07
    Signal v. Noise: Basecamp’s January 2019 mass-login attack disclosure - Primary vendor account of the credential-stuffing attack
  8. 08
    Have I Been Pwned: breached-sites index - Source for the separately scoped HIBP coverage table; checked July 13, 2026

A smaller blast radius, by design.

No service is immune to incidents — SealTask included. For a compromise limited to content already stored by the service, protected workspace content is present as ciphertext. Account metadata, active sessions, client delivery, and devices remain separate risks. Judge the architecture yourself.