Millions of Trello user accounts leaked online — personal info available for basically nothing, here's what we know

Trello
(Image credit: Trello)

Public account information on more than 15 million Trello users has been leaked online after a threat actor decided to basically give it away on a hacking forum. 

In January 2024, a threat actor with the alias ‘emo’ said they collected 15,115,516 email addresses used to register Trello accounts, by feeding more than 500 million emails into an unsecured API, to see which were used for an account on the platform. Besides the email address, the hacker obtained people’s public Trello account information, as well as full names.

Fast-forward roughly half a year later, and the same threat actor is now selling the database on the Breached hacking forum for eight site credits. According to BleepingComputer, that equals $2.32.

Abusing APIs

"Trello had an open API endpoint that allows any unauthenticated user to map an email address to a trello account," the threat actor said. "I originally was only going to feed the endpoint emails from 'com' (OGU, RF, Breached, etc.) databases but I just decided to keep going with emails until I was bored."

Initially, Trello denied having been breached, and said that the hacker built the database out of public and scraped information. Now, it confirmed that the incident stemmed from an unsecured API:

"Enabled by the Trello REST API, Trello users have been enabled to invite members or guests to their public boards by email address. However, given the misuse of the API uncovered in this January 2024 investigation, we made a change to it so that unauthenticated users/services cannot request another user's public information by email. Authenticated users can still request information that is publicly available on another user's profile using this API. This change strikes a balance between preventing misuse of the API while keeping the ‘invite to a public board by email’ feature working for our users. We will continue to monitor the use of the API and take any necessary actions."

While collecting public information this way doesn’t sound like a particularly dangerous attack, the information can still be used to create convincing phishing emails. That can lead to more destructive compromise, such as password theft, malware deployment, and more.

Trello is a project management platform on which users (mostly businesses) can organize tasks into columns, or cards. The platform allegedly has more than 40 million users.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
Top collectibles site leaks personal data of nearly a million users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Latest in Security
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
A digital representation of blockchain.
Malicious npm packages use devious backdoors to target users
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
Latest in News
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Nintendo Switch 2
The Nintendo Switch 2 pre-order date has seemingly been confirmed by Best Buy Canada – here's when you'll be able to order yours
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long