Trello is a popular project management tool that's well-known for its kanban-style list format.
On Tuesday, the private data connected to 15,115,516 Trello user profiles was shared on a popular forum for hackers, as first noticed by the cybersecurity news website Bleeping Computer. It appears that a single hacker discovered a flaw in Trello's system and was able to extract sensitive private user data.
While much of the data connected to a Trello account is public information, not all of it is. By far, the most concerning part of the breach for Trello users is the email address data.
Over 15 million Trello users now have their private email addresses associated with their Trello profiles exposed to the public.
The Trello data breach and subsequent leak can be traced back to earlier this year. Bleeping Computer first noticed in January that the hacker, with the moniker "emo," was selling the Trello data on the hacking forum before providing greater access to it this week.
Both Trello's parent company, Atlassian, and "emo" (the hacker), have since shared more information about how this leak came to be.
According to a forum post by the hacker, they discovered that "Trello had an open API endpoint that allows any unauthenticated user to map an email address to a trello account." In a correspondence with Bleeping Computer, the hacker further explained that once they discovered the flaw, they put together a list of hundreds of millions of email addresses and cross checked them with the Trello accounts in the API. From there, "emo" was able to link those email addresses with Trello accounts and create a user profile for more than 15 million accounts.
Atlassian confirmed the issue with Bleeping Computer in a statement, saying that the Trello REST API was intended to allow Trello users to invite guests to public boards through email. The company has updated the Trello API to preserve this feature while preventing its misuse by bad actors.
"Given the misuse of the API uncovered in this January 2024 investigation, we made a change to it so that unauthenticated users/services cannot request another user's public information by email," Atlassian said in its statement. "Authenticated users can still request information that is publicly available on another user's profile using this API. This change strikes a balance between preventing misuse of the API while keeping the ‘invite to a public board by email’ feature working for our users. We will continue to monitor the use of the API and take any necessary actions."
Fixing the issue is certainly a step in the right direction. Unfortunately, the leaked data that was obtained through this method is still out there. And if one wonders exactly what can be done with this data, "emo" the hacker shared exactly why the Trello leak is useful to bad actors in their forum post.
"This database is very useful for doxing," wrote emo, who explained one can simply match the email address to a full name or alias attached to a Trello account using the stolen data.
Trello users should be aware that this sensitive data is out there.
Copyright © 2023 Powered by
Trello leak: Over 15 million email addresses exposed. How did this happen?-如火燎原网
sitemap
文章
485
浏览
21
获赞
691
'Archive zombies' will crawl back into your messages long after your interest has died
It was a Monday night at precisely 21:09 p.m. when I got a text from an unknown number."Hi," it declThe best porn alternatives that are entirely SFW
Welcome to Porn Week, Mashable's annual close up on the business and pleasure of porn.Most people unEV company Fisker wants to build Pope Francis an electric Popemobile
Pope Francis' next ride could be battery powered.Henrik Fisker, co-founder of California-based carmaWe worked in a VR office during lockdown to get over Zoom fatigue
I didn't know the closest I'd get to bonding with my coworkers in 2020 would be by strapping a screeFacebook engineer quits, says company is 'profiting off hate'
A Facebook engineer has published a scathing resignation letter accusing the company of "profiting o12 of the best dating memes
Dating in 2020 is certainly different than dating in previous years because of... well, you know. EvThe best porn alternatives that are entirely SFW
Welcome to Porn Week, Mashable's annual close up on the business and pleasure of porn.Most people unAdobe's Flash Updater: Bloated, Confusing & Shady
Editorial Being one of the most prolific sources of security vulnerabilities in Windows and other plChrissy Teigen accidentally leaks her email address on Twitter, styles it out
If you're an average Joe who accidentally tweets out their personal email address, chances are not aI quit Amazon Prime a year ago. I don't miss it.
In May of last year, I canceled my Amazon Prime membership.The pandemic had just devastated New YorkEV company Fisker wants to build Pope Francis an electric Popemobile
Pope Francis' next ride could be battery powered.Henrik Fisker, co-founder of California-based carmaAmericans woke to 'demon sperm' trending on Twitter
Life for the perpetually online: you rise from slumber, rub the sleep from your eyes, take a deep siBoomers killed the Facebook status
Few leisure activities bring boomers more satisfaction than complaining about millennials, but usingThe best porn alternatives that are entirely SFW
Welcome to Porn Week, Mashable's annual close up on the business and pleasure of porn.Most people unDrum battle between Dave Grohl and 10
In his latest play in the ongoing rock battle with Nandi Bushell, Dave Grohl improvised a superhero