Device, identity and access management solutions provider JumpCloud has reset customer API keys in response to an “ongoing incident”.
JumpCloud has yet to share any information, but notifications sent to customers suggest that it’s dealing with a security incident. The company said existing API keys have been invalidated to protect the customer’s “organization and operations”.
“We apologize for any disruption this causes you and your organization,” the company told users, “but the action was taken on your behalf as the most prudent course of action.”
While JumpCloud’s status pages make no mention of the incident, the company has published a support page informing admins that all API keys have been invalidated, impacting several features and integrations. The page provides instructions for generating new API keys.
“Out of an abundance of caution relating to an ongoing incident, JumpCloud has decided to invalidate all API Keys for JumpCloud Admins,” reads a message on that support page.
SecurityWeek has reached out to JumpCloud for more information and will update this article if the company responds.
Related: JumpCloud Raises $159 Million at $2.56 Billion Valuation
Related: Thousands of Secret Keys Found in Leaked Samsung Source Code
Related: Leaked Algolia API Keys Exposed Data of Millions of Users
Related: Credential Leakage Fueling Rise in API Breaches