Skip to main content
Breach Signal

Breach report

Cloud & SaaS

Trello (Atlassian)

Email addresses of 15 million Trello users leaked on hacking forum

A threat actor abused an open Trello API to match 500 million email addresses against accounts, building a list of about 15 million Trello users that was leaked on a hacking forum in July 2024.

Reported by BleepingComputer

Records exposed

15.1M

About 15.1 million accounts

Scale vs. largest on file

When
2024
How they got in
API abuse (unauthenticated endpoint linking email addresses to accounts)
Sector
Cloud & SaaS

In January 2024, a threat actor using the name emo offered a dataset of more than 15 million Trello user profiles for sale on a hacking forum. The data had not been stolen from Trello's databases in a conventional intrusion. Instead, the actor had exploited a publicly accessible application programming interface that allowed anyone, without logging in, to look up a Trello profile by email address. In July 2024, the same actor released the dataset of 15,115,516 records on the Breached forum for a token price, making it widely available.

According to the hacker, a list of roughly 500 million email addresses was fed into the Trello endpoint to see which ones corresponded to accounts. Each match returned the user's public profile information, including username and full name, which could then be tied to the private email address that produced it. The result was a directory that connected people's email addresses with their Trello identities, something Trello users had not made public.

Atlassian, which owns the project management tool, said in January that the data appeared to have been obtained by querying public profile information and that it had found no evidence of unauthorized access to its systems. After the July release, the company confirmed that the API had allowed the lookups and said it had changed it so that unauthenticated users and services could no longer request another user's public information by email address. Breach-notification service Have I Been Pwned added the data so users could check whether they were included.

No passwords or payment data were involved, and no regulatory action was announced. However, security experts noted that a list linking email addresses to a specific work-collaboration tool is valuable for targeted phishing, since attackers can craft convincing fake notifications that appear to come from Trello. Because many Trello users rely on it for business projects, the data could also help criminals identify corporate targets.

The Trello incident belongs to a growing category of scraping and enumeration attacks in which APIs designed for convenience are abused at scale, similar to earlier cases involving Twitter, Facebook and Duolingo. It shows that data exposure does not require a break-in; an endpoint that confirms whether an email is registered can be enough. For platform operators, the lesson is to require authentication and rate limiting on lookup features.

More from the wire

More in Cloud & SaaS.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.