EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2024-trello-data-scrape
082/430

File EL-0349MediumResolvedData Breach / Account Scraping / API Abuse

Trello Data Scrape

Also filed as Trello Email Scrape 2024 · Trello Data Leak

A threat actor scraped 15 million email addresses associated with Trello accounts by exploiting an unauthenticated API endpoint that mapped email addresses to public Trello profiles.

  • #trello
  • #atlassian
  • #data-scraping
  • #email-addresses
  • #api-abuse
  • #pii
Notoriety7/10
Event
15 Jul 2024
Disclosed
15 Jul 2024
Target
Trello (Atlassian)
Actor
Unknown Hacker
Scale
15.0M people
Status
Resolved

01Summary

In July 2024, a threat actor scraped approximately 15 million email addresses associated with Trello accounts by abusing a GraphQL API endpoint. The API allowed anyone to check if an email address had a public Trello profile and return the associated username and other public information. By enumerating large lists of email addresses, the attacker compiled a database of 15M email-Trello account mappings, which was posted on BreachForums. Atlassian confirmed the data was obtained using a previously reported API feature designed for discoverability.

02Background

Trello is a popular project management tool owned by Atlassian, used by millions of individuals and organizations worldwide.

03Key revelations

  1. 01Trello's email-to-account lookup feature enabled large-scale scraping
  2. 02Design trade-offs between discoverability and privacy created risk
  3. 0315M accounts could be enumerated without any rate limiting bypass

04Technical analysis

The attacker used Trello's GraphQL API endpoint that accepted email addresses and returned whether they were associated with a public Trello account. This discoverability feature was intentional but allowed bulk enumeration when combined with large email lists from other breaches. No authentication bypass was involved; the API functioned as designed.

05Threat actor

The perpetrator remains unidentified. The attack methodology suggests a data aggregator or threat actor building enrichment databases for use in credential stuffing and social engineering campaigns.

Attribution sources

  • BreachForums posts

06Victims and impact

The scraped email addresses could be used for credential stuffing attacks, targeted spam, and phishing campaigns targeting individuals known to use Trello for specific projects.

Evidence of breach

The dataset was posted on BreachForums and verified by cybersecurity researchers. Atlassian confirmed the scrape.

Countries affected

  • Global

07Data exposed

Data types

  • Email Addresses
  • Trello Usernames
  • Public Profile Information

08Financial damage

No direct financial damage. Primarily risk of secondary attacks on affected users.

09Timeline

  1. 2024-07-15Dataset of 15M emails posted on BreachForums
  2. 2024-07-16Atlassian confirms scrape, implements rate limiting

10Reaction and fallout

Public reaction

Concern among Trello users about privacy and the ability to associate email addresses with project management data.

11Legal

Atlassian declined to change the API behavior, stating it was a planned feature for collaboration.

12Aftermath

Security improvements

  • Atlassian added rate limiting to the affected API endpoint

13Significance and legacy

Significance

The Trello scrape demonstrated how legitimate API features designed for collaboration could be weaponized for bulk data collection, highlighting the privacy risks of email-to-account lookup functionality.

Legacy

Served as a case study for companies designing social/team features that expose email-to-account mappings, contributing to industry discussion about rate limiting and privacy-by-design.

14Disclosure and media

Authentication
Verification of sample data by multiple security researchers

Publishing organisations

  • BleepingComputer
  • HackRead
  • CyberNews

15Field notes

  1. 01The attacker reportedly used a list of 500M email addresses compiled from other data breaches to query Trello's API.
  2. 02Trello's API was designed to allow team members to find each other by email - a feature that inadvertently enabled this large-scale scrape.

16Resolution

Atlassian implemented rate limiting on the GraphQL API endpoint. The underlying feature remained active as it was considered a core collaboration function.

17Sources

References

  1. [1]BleepingComputer
  2. [2]Atlassian official statement
Fact sheetEL-0349

Dates

Event
15 Jul 2024
Duration
1 days
Discovered
15 Jul 2024
Disclosed
15 Jul 2024
Resolved
16 Jul 2024
Ongoing
No

Target

Organisation
Atlassian Corporation
Type
Technology Company
Sector
Software
Country
Australia

Actor

Name
Unknown Hacker
Type
Solo Actor
Motivation
Collection of email addresses for credential stuffing and spam
Attribution
Low
Arrested
No
Convicted
No

Data

People
15,000,000
Sensitivity
Public
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.