logo

Atlassian Tightens API After Hacker Scrapes 15M Trello Profiles

ID: 1e62ffc6-106f-582b-99d9-d56722dd15f4

STIX ID: report--1e62ffc6-106f-582b-99d9-d56722dd15f4

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-01-24

Date Updated: 2026-05-05

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

**Executive summary:** An attacker scraped roughly 15 million Trello public profiles by abusing an unauthenticated API endpoint that returned user profile data when queried by email; the dataset (usernames and emails) was put up for sale on the dark web, and Atlassian has since tightened the API to block unauthenticated email-based profile queries while leaving authenticated public-profile access intact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.