Smartsheet Logo

Smartsheet Status

This page provides status information for Smartsheet features and functionality. Check back here to view our most up-to-the-minute information on service availability, or click the button above to be notified of interruptions to each individual service. If you are experiencing an issue not listed here try troubleshooting connection issues.

 
 

Increased spam activity with Smartsheet Forms

Incident Report for Smartsheet

Postmortem

Starting in late May, we observed a marked increase in volume and sophistication of spam submissions to public Smartsheet Forms (forms available to the general public and not requiring a Smartsheet login), even with the Captcha setting enabled. This resulted in some customers experiencing an increase in unwanted spam content, frequently containing cryptocurrency or phishing links, delivered into their sheets. The activity was generated by automated bots operating through anonymized networks and proxy services. This primarily impacted but was not limited to the US region.

Once the abuse was identified, we evaluated, deployed, tested, and tuned a series of protective measures over the following weeks. Because automated abuse of this kind adapts over time, addressing it requires an iterative approach: we layered multiple protections in both forms, captcha service, and the underlying infrastructure, evaluated their effectiveness against live traffic, and refined them as we learned more, adjusting or replacing measures that proved less effective. Throughout this process we also monitored and worked to correct any unintended impact to legitimate form submissions which may have occurred during this period. Automated spam is now substantially blocked down to virtually zero pass through rate and with minimal or no impact on legitimate submissions. We are also actively bringing similar protections into the Smartsheet Gov environment. As of 1:46PT, July 8th, we marked this issue as resolved.

If you are still observing spam submissions please first ensure you have Captcha enabled on the form. If Captcha is enabled and you are still seeing spam, please submit a report using the “report abuse” link on your form. We always recommend applying the highest level of forms security restriction compatible with your solution and if necessary enforce form security from the admin center.

We will continue to monitor, tune, and strengthen these protections ongoing. This includes changes to have Captcha enabled by default for all new forms and new administrative controls rolling out for system admins to have the ability to enforce Captcha for forms managed by their plan.

We know how critical our services are to our customers and apologize for any impact this incident may have had on you and your business. We promise that we will do everything we can to learn from this event and use it to drive improvement across our services to ensure that Smartsheet is a partner that can be counted on to deliver. We know that your success — and your continued trust in Smartsheet — depends on it.

Posted Jul 17, 2026 - 16:16 PDT

Resolved

This is now resolved. We are still actively monitoring spam levels as an ongoing and evolving strategy. We encourage all customers to submit support tickets for any residual spam coming through so we can continue to fine tune our solutions.
Posted Jul 08, 2026 - 13:46 PDT

Monitoring

We have implemented measures to address the increased spam activity with Smartsheet public forms. We will continue monitoring and make further adjustments as needed.

If you are continuing to see a high rate of spam submissions, please contact our support team so that we can investigate further.
Posted Jun 23, 2026 - 00:44 PDT

Identified

We are aware that some customers are receiving an increased volume of unwanted spam submissions through public Smartsheet forms, even with reCAPTCHA enabled. Our teams have been actively investigating and deploying additional protections. We are observing a decrease in spam activity as we continue applying and evaluating further mitigations.

Who is affected:
Customers who use public forms that do not require login.
Posted Jun 18, 2026 - 14:42 PDT
This incident affected: Core Application (Forms).