Trello API abused to link email addresses to 15 million accounts
ID: fb3430d4-7c71-5d1d-9d4d-f3ba8c91f0c8
STIX ID: report--fb3430d4-7c71-5d1d-9d4d-f3ba8c91f0c8
Feed Name: Bleeping Computer
A threat actor leveraged an unauthenticated Trello REST API endpoint to confirm and link ~15.1 million private email addresses with public Trello profiles, compiling a dataset of emails, usernames, and full names that was put up for sale; Atlassian reports the method involved querying the API with email addresses and using proxies to bypass rate limits. Trello has since changed the endpoint to require authentication, and while there is no evidence of unauthorized system access, the linkage of private emails to public profiles increases the risk of targeted phishing and other privacy harms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
