An exposed Trello API allowed the linking of private email addresses with Trello accounts, potentially creating millions of data profiles containing both public and private information.
The data leak surfaced when an individual going by the alias ‘emo’ tried to sell the data of over 15 million Trello members on a prominent hacking forum.
The post on the hacking forum said the information of the affected users included emails, usernames, full names and more. While a lot of the data in these profiles are public, the main concern lies in the exposure of the email addresses of the associated profiles.
Trello Allegedly Breached: Database of 15,115,516 User Records Up for Sale
The cybercriminal, who goes by the name 'emo,' claims that the database includes data such as emails, usernames, full names, and other account information.#databreach #CTI #DarkWeb pic.twitter.com/Fim9jOwUzn
— HackManac (@H4ckManac) January 17, 2024
According to Atlassian, the owner of Trello, the data was not obtained through unauthorised access to Trello’s systems but by scraping public data.
“All evidence points to a threat actor testing a pre-existing list of email addresses against publicly available Trello user profiles. The security and privacy of our users’ data is our highest priority, and we continue to monitor Trello closely for any unusual activity,” said a Trello spokesperson according to Forbes.
However, in a Bleeping Computer investigation, it seems the threat actor had used a publicly exposed API to associate email addresses with public Trello profiles. This conclusion was reached after the publication allegedly spoke with ‘emo,’ the culprit of the breach.
Trello offers a REST API, which allows developers to integrate the service into their applications. The API endpoint, initially intended for querying public information based on Trello ID or username, was found to also respond to queries using an email address.
Notably, the API was publicly accessible, meaning it could be queried without logging into a Trello account or using an API authentication key. The threat actor compiled a list of 500 million email addresses and fed them into the API to identify Trello accounts. The API, now hardened to require authentication, was reportedly constantly queried using proxy servers.
Recommended
- Atlassian Customers Face Lengthy Disruption After Cloud Outage
- Which Data Breaches Had Everyone Talking This Year?
- Human Error Spurs Data Breach Surge
Trello claims to have made changes to the API covered in the investigation, so that unauthenticated users cannot request other users public information by email.
While publicly scraped data is normally not a concern, email address exposure elevated the security of the leak, since it could be used in targeted phishing campaigns.
The Trello leak has since been added to the Have I Been Pwned website, allowing individuals to check if their email address has been compromised.





