JumpCloud reset API keys following security incident

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

JumpCloud has confirmed it reset customer API keys following a “security incident” earlier in July 2023, leaving customers who missed the advisory notice with disrupted services.

In a blog post, company CISO Bob Phan explained: “The security threats that we face, as an industry, are unprecedented and require strong collaboration from all constituents.”

Details of the security incident remain sparse, but Phan disclosed that unauthorized access by a sophisticated nation-state-sponsored threat actor saw a “small and specific” set of cloud storage customers targeted, who were notified prior to the public blog post.

JumpCloud security incident

In response to the attack, JumpCloud says that it has been working with both incident response partners and law enforcement in order to prevent such future attacks, claiming that “the attack vector used by the threat actor has been mitigated.”

The API key reset on July 5 followed “unusual activity in the commands framework” on the same day. Phan said that the spear-phishing campaign could be traced back to June 22.

Despite expressing a commitment to providing “ transparent and timely information,” some have expressed their concern over the incident.

Nick Rago, Field CTO at Salt Security, a company whose mission it is to make APIs attack-proof, said that the incident must have been “pretty significant” for JumpCloud to have taken the action it did across its whole customer base.

Rago continued: “there doesn't seem to be much transparency at this time into what the security incident was or how long API keys might have been potentially exposed, or how they are remedying this type of incident from happening again.”

Salt Security’s Field CTO suggests that enterprise users should look to lock down API access to their account from a whitelist of locations in order to limit attack risk.

JumpCloud’s Phan promised that the company would continue to enhance its security measures to prevent future attacks, collaborating with industry partners and governments. 

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
Data leak
AWS customers hit by major cyberattack which then stored stolen credentials in plain sight
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Holographic representation of cloud computing over open businessman's hand
AWS, Azure and Google Cloud credentials from old accounts are putting businesses at risk
Avast cybersecurity
Zapier tells customers their data may have been accessed
vpn
Nominet says it was hit by cyberattack following recent Ivanti VPN security issue
Latest in Pro
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
AOC Graphic Pro U32U3CV during our review
I reviewed the AOC Graphic Pro U32U3CV and it's a staggeringly pro-grade monitor for the price
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day