The short answer
Asana disclosed that a flaw in its Model Context Protocol implementation potentially made certain information in some customer instances accessible to users from other Asana customers. Asana described the event as a logic or implementation flaw, not an external hack into its systems. [1][2]
The feature launched on May 1, 2025, Asana discovered the issue on June 4, and reporting said roughly 1,000 customers could have been affected. Asana took the feature offline, sent notices to impacted organizations, and its status page showed the feature back to normal operation on June 17. The public sources describe potential access; they do not establish that every potentially exposed record was actually viewed by another customer. [1][2]
This record covers the cross-customer data-exposure risk in Asana’s Model Context Protocol feature between May and June 2025. It does not establish that Asana’s wider service was breached or that every customer workspace was exposed. [1][2]
Classification: Data became accessible to unintended people because of a bug or configuration error. Learn how incident terms differ.
Classification
Cross-customer data exposure caused by an MCP implementation flaw; not a confirmed external intrusion [1][2]
Feature window
MCP launched May 1, 2025; issue discovered June 4; status returned to normal June 17 [2]
Potential reach
Roughly 1,000 customers, according to an Asana spokesperson quoted by BleepingComputer [2]
Possible data
Task information, project metadata, team details, comments or discussions, and uploaded files within the affected user’s existing access scope [2]
Publicly established impact
Potential unintended access; the cited disclosures do not quantify confirmed cross-customer views [1][2]
Response
Feature taken offline, impacted organizations notified, status returned to normal operation June 17 [2]
Incident timeline.
-
Asana launches its MCP feature
Asana makes the feature available so AI tools can interact with Asana data under a user’s permissions. The later-disclosed implementation flaw is present during this release window. [2]
-
Issue discovered and feature taken offline
Asana identifies the logic flaw and disables MCP while investigating whether data from one customer organization could be returned to a user associated with another. [1][2]
-
MCP returns to normal operation
Asana’s status page shows MCP returning to normal operation. Reporting says Asana sent notices with communication-form links to each impacted organization. [2]
-
Asana describes the issue in an SEC filing
Asana’s quarterly filing records that a June 2025 MCP implementation flaw potentially made certain data in some customer instances accessible to other users of the feature. [1]
What happened in Asana’s MCP feature
Model Context Protocol connectors let an AI client request data from another service. In Asana’s implementation, a logic flaw could cross the customer boundary: a request made by a user from one organization could potentially receive information from another customer instance. This was an authorization and data-isolation failure in the feature, rather than evidence that an attacker broke into Asana infrastructure. [1][2]
Asana’s SEC filing uses conditional language: certain data was “potentially” accessible. BleepingComputer likewise reported possible exposure and said Asana did not characterize the incident as a hack. The sources do not support treating every customer in the estimated population as having confirmed data access by another organization. [1][2]
What data could have crossed the customer boundary
According to notices described by BleepingComputer, possible data included task-level information, project metadata, team details, comments or discussions, and uploaded files. Access remained tied to what the affected Asana user was already authorized to reach; the incident was not described as making an entire workspace public. [2]
An Asana spokesperson told BleepingComputer that roughly 1,000 customers could have been affected. That estimate is the potential customer population reported publicly, not a count of confirmed data disclosures or individual records viewed. [2]
Asana’s response
Asana took MCP offline after discovering the issue on June 4, sent notices with communication-form links to impacted organizations, and returned the feature to normal operational status on June 17. [2]
Customers evaluating the event should preserve the distinction between potential and observed access. The public materials identify the vulnerable window and data classes but do not provide a public per-customer audit of which records, if any, another organization actually retrieved. [1][2]
What Asana customers should review
Organizations that received an Asana notice should use its stated affected-data categories as the starting point, then review connected AI clients, MCP access, user permissions, and any sensitive files or conversations within the named scope. Affected organizations may also need to assess their own notification or contractual duties based on the data they stored. [2]
The event is also a reason to treat AI connectors as an authorization boundary, not merely an interface feature. Limit connector access to the users and projects that need it, and retain logs capable of showing which resources a connected client requested. [1][2]
How SealTask relates to this incident class
Cross-customer disclosure of readable workspace content is the incident class most relevant to SealTask’s client-side encryption. SealTask stores protected task content as ciphertext, which can reduce what a passive server-side stored-data disclosure reveals. That property does not prove it would have prevented every path in Asana’s MCP incident, and it does not protect server-visible metadata, account access, authorized clients, active sessions, or compromised devices. [4]
Frequently asked questions.
Was Asana hacked in 2025?
The cited disclosures describe an implementation or logic flaw in Asana’s MCP feature, not an external hack into Asana systems. The flaw could potentially return some customer data to a user from another customer organization. [1][2]
How many Asana customers were affected?
An Asana spokesperson told BleepingComputer that roughly 1,000 customers could have been affected. That is a potential-scope estimate, not a count of confirmed cross-customer data views. [2]
What Asana data could have been exposed?
Reported categories included task information, project metadata, team details, comments or discussions, and uploaded files, bounded by the affected user’s existing permissions. [2]
When did Asana restore the MCP feature?
Asana discovered and disabled the affected feature on June 4, 2025. Its status page returned to normal operational status on June 17; the cited public sources do not describe further verification steps. [2]
Related records
Sources
All sources last accessed . Corrections: email hello@sealtask.com with a source and we will review and correct.
- 01 Asana Form 10-Q for the quarter ended July 31, 2025 - Primary company filing — the June 2025 MCP implementation flaw and its conditional cross-user scope
- 02 BleepingComputer: “Asana warns MCP AI feature exposed customer data to other orgs” - Contemporaneous reporting — launch and restoration dates, potential customer count, and possible data categories
- 03 Have I Been Pwned: breached-sites index - No product-attributed Asana entry located; checked against the live index on July 13, 2026
- 04 SealTask security architecture - What SealTask encrypts client-side and which account and operational metadata remain server-visible
Prefer task content protected at rest?
SealTask encrypts task titles, notes, comments, and attachments before upload. A compromise limited to stored server data would expose ciphertext for that content; account metadata, active sessions, client delivery, and devices remain separate risks.