Trello data on 15 million users leaked after an open API was scraped
- Organization
- Atlassian (Trello)
- Exploit
- Hacking
- Industry
- Software
A dataset covering more than 15 million Trello accounts was published on the Breached hacking forum in mid-July 2024, roughly six months after it was assembled. Trello is a project management tool owned by Atlassian. The records included user IDs, usernames, full names, profile URLs, account status, settings and board membership details, alongside about 15.1 million email addresses.
The person who posted the data, using the handle "emo", had first offered it for sale in January 2024. According to that account, Trello exposed a REST API endpoint that let an unauthenticated user map an email address to a Trello account. The attacker fed a list of around 500 million random email addresses into the endpoint and kept every address that matched an account.
Most of the profile fields involved were already public. The email addresses were not, and their pairing with real names is what made the compilation useful for phishing and doxxing. SiliconANGLE and IT Pro reported the leak on July 17, 2024. No passwords were included.
Atlassian said its investigation found no evidence that the data was gathered through unauthorized access, and characterized the incident as a threat actor testing a pre-existing list of addresses against publicly available Trello profiles. The company said that after the January activity it changed the API so unauthenticated users and services could not request another user's public profile by email address, while leaving the feature available to authenticated users, and that it would keep monitoring the endpoint.