The short answer
monday.com disclosed that the Codecov supply-chain compromise affected its development environment and allowed an attacker to access a read-only copy of its source code. The attacker also accessed a file listing certain URLs for customer forms and views that had been made public through monday.com’s sharing features. [1][2]
monday.com said it had seen no indication that customer data was affected and found no evidence of unauthorized source-code modification or product impact. It contacted the customers connected to the public URLs and told them how to regenerate those links. [1][3]
This record covers monday.com’s disclosed downstream impact from the 2021 Codecov supply-chain compromise: access to a read-only copy of source code and a file listing URLs for public customer forms and views. monday.com said it found no indication that customer data was affected. [1][2]
Classification: A third-party tool or dependency was compromised and used to reach the vendor. Learn how incident terms differ.
Classification
Supply-chain compromise through Codecov, with downstream source-code access at monday.com [1][2]
Activity window
monday.com says it became aware of the Codecov incident in April 2021 [2]
Confirmed access
A read-only copy of monday.com source code and a file containing certain public customer-form and view URLs [1]
Customer-linked material
Certain URLs pointing to public customer forms and views; relevant customers were told how to regenerate them [1]
Customer product data
monday.com said it had seen no indication that customer data was affected [1]
Code integrity
monday.com said it found no unauthorized source-code modification or product impact [1]
Incident timeline.
-
monday.com becomes aware of Codecov impact
monday.com becomes aware that Codecov, its SaaS code-testing provider, had experienced unauthorized access capable of exporting information from customers’ continuous-integration environments. monday.com revokes Codecov access, stops using the service, rotates production and development keys, and retains outside forensic experts. [2][3]
-
F-1 filing documents source-code and public-URL access
In its IPO registration statement, monday.com says a read-only copy of source code and a file listing public customer-form and view URLs were accessed. It reports no indication of affected customer data, no unauthorized source modification, and no product impact at that point. [1]
-
Annual report preserves the incident record
monday.com’s annual report again identifies the Codecov event as a security incident and says the attacker was able to export a read-only copy of its source code. [2]
How Codecov access reached monday.com
Codecov was monday.com’s third-party SaaS code-testing provider. Codecov’s compromised uploader could export information from customer continuous-integration environments; monday.com subsequently found evidence that a read-only copy of its source code had been accessed. That makes this a supply-chain event: the initial compromise occurred at a trusted development vendor and produced downstream impact at monday.com. [1][2][3]
monday.com said it found no evidence that the source code was changed and no impact on its products. Read-only source access still matters because copied code can reveal architecture or information useful for identifying later attack paths, even when the attacker cannot commit a modification. [1]
What was copied — and the customer-data boundary
The two confirmed material classes were a read-only copy of source code and a file containing certain URLs for customer forms and views that had been publicly shared. monday.com contacted the relevant customers and explained how to regenerate those URLs. [1][3]
The company separately said it had seen no indication that customer data was affected. Access to public-sharing URLs should therefore not be rewritten as a confirmed compromise of private monday.com boards or general workspace content. [1][3]
monday.com’s response
monday.com revoked Codecov access, discontinued the service, rotated keys for its production and development environments, and retained outside cybersecurity forensic experts. It also contacted customers connected to the public form and view URLs in the accessed file. [1][3]
The company’s “no indication” and “no evidence” statements describe the state of its investigation at the time, not proof that no unlogged access occurred. They do set the boundary of what the cited record supports: source-code and public-URL access was confirmed; affected customer data, code tampering, and product impact were not. [1]
What this incident teaches buyers and engineering teams
Development tools should receive the minimum repository and secret access they need, with short-lived credentials, rapid rotation, and logs outside the tool’s own control. Public sharing links also belong in secret-scanning and repository-review rules even when the linked resources were intentionally public at creation time. [1][3]
Customers relying on public forms or views should inventory and rotate links when a vendor tells them those URLs may have been copied. This incident did not establish a need for every monday.com customer to reset a password or assume that private boards were read. [1][3]
How SealTask relates to this incident class
Client-side encryption of task content would not prevent a compromised development supplier from exposing source code, CI credentials, or public sharing links. SealTask’s narrower protection is that readable workspace content is encrypted before server storage, which can reduce the content exposed by a passive stored-data compromise. It does not remove software supply-chain, account, metadata, client, device, or session risk. [5]
Frequently asked questions.
Was monday.com breached through Codecov?
monday.com confirmed that a read-only copy of its source code was accessed through the Codecov supply-chain compromise. It said it had seen no indication that customer data was affected. [1][2]
What monday.com information did the Codecov attacker access?
Confirmed material included a read-only copy of source code and a file containing certain URLs for public customer forms and views. [1]
Were private monday.com boards exposed?
The cited sources do not establish that. monday.com said it had seen no indication that customer data was affected; the documented customer-linked material was a file of URLs for forms and views that had been publicly shared. [1][3]
Did the attacker modify monday.com source code?
monday.com said it found no evidence of unauthorized source-code modifications and no impact on its products as of the F-1 filing. [1]
Related records
Sources
All sources last accessed . Corrections: email hello@sealtask.com with a source and we will review and correct.
- 01 monday.com Form F-1 filed May 17, 2021 - Primary company filing — source-code access, public customer URLs, investigation caveats, and customer outreach
- 02 monday.com 2021 annual report filed with the U.S. SEC - Primary company filing — April 2021 awareness and the exported read-only source-code copy
- 03 BleepingComputer: “Codecov hackers gained access to monday.com source code” - Contemporaneous reporting — public form and view URLs, customer outreach, and May 2021 company statements
- 04 Have I Been Pwned: breached-sites index - No product-attributed monday.com entry located; checked against the live index on July 13, 2026
- 05 SealTask security architecture - What SealTask encrypts client-side and which account and operational metadata remain server-visible
Prefer task content protected at rest?
SealTask encrypts task titles, notes, comments, and attachments before upload. A compromise limited to stored server data would expose ciphertext for that content; account metadata, active sessions, client delivery, and devices remain separate risks.