Site navigation

Trello Email Breach Affects Over 15 Million Users

Michael Edgar

,

Trello breach
A data leak on the project management platform Trello exposes private email addresses, putting millions at risk. 

An exposed Trello API allowed the linking of private email addresses with Trello accounts, potentially creating millions of data profiles containing both public and private information. 

The data leak surfaced when an individual going by the alias ‘emo’ tried to sell the data of over 15 million Trello members on a prominent hacking forum.

The post on the hacking forum said the information of the affected users included emails, usernames, full names and more. While a lot of the data in these profiles are public, the main concern lies in the exposure of the email addresses of the associated profiles. 

According to Atlassian, the owner of Trello, the data was not obtained through unauthorised access to Trello’s systems but by scraping public data. 

“All evidence points to a threat actor testing a pre-existing list of email addresses against publicly available Trello user profiles. The security and privacy of our users’ data is our highest priority, and we continue to monitor Trello closely for any unusual activity,” said a Trello spokesperson according to Forbes. 

However, in a Bleeping Computer investigation, it seems the threat actor had used a publicly exposed API to associate email addresses with public Trello profiles. This conclusion was reached after the publication allegedly spoke with ‘emo,’ the culprit of the breach. 

Trello offers a REST API, which allows developers to integrate the service into their applications. The API endpoint, initially intended for querying public information based on Trello ID or username, was found to also respond to queries using an email address.

Notably, the API was publicly accessible, meaning it could be queried without logging into a Trello account or using an API authentication key. The threat actor compiled a list of 500 million email addresses and fed them into the API to identify Trello accounts. The API, now hardened to require authentication, was reportedly constantly queried using proxy servers.


Recommended


Trello claims to have made changes to the API covered in the investigation, so that unauthenticated users cannot request other users public information by email. 

While publicly scraped data is normally not a concern, email address exposure elevated the security of the leak, since it could be used in targeted phishing campaigns. 

The Trello leak has since been added to the Have I Been Pwned website, allowing individuals to check if their email address has been compromised. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data