01Summary
In July 2024, a threat actor scraped approximately 15 million email addresses associated with Trello accounts by abusing a GraphQL API endpoint. The API allowed anyone to check if an email address had a public Trello profile and return the associated username and other public information. By enumerating large lists of email addresses, the attacker compiled a database of 15M email-Trello account mappings, which was posted on BreachForums. Atlassian confirmed the data was obtained using a previously reported API feature designed for discoverability.
02Background
Trello is a popular project management tool owned by Atlassian, used by millions of individuals and organizations worldwide.
03Key revelations
- 01Trello's email-to-account lookup feature enabled large-scale scraping
- 02Design trade-offs between discoverability and privacy created risk
- 0315M accounts could be enumerated without any rate limiting bypass
04Technical analysis
The attacker used Trello's GraphQL API endpoint that accepted email addresses and returned whether they were associated with a public Trello account. This discoverability feature was intentional but allowed bulk enumeration when combined with large email lists from other breaches. No authentication bypass was involved; the API functioned as designed.
05Threat actor
The perpetrator remains unidentified. The attack methodology suggests a data aggregator or threat actor building enrichment databases for use in credential stuffing and social engineering campaigns.
Attribution sources
- BreachForums posts
06Victims and impact
The scraped email addresses could be used for credential stuffing attacks, targeted spam, and phishing campaigns targeting individuals known to use Trello for specific projects.
Evidence of breach
The dataset was posted on BreachForums and verified by cybersecurity researchers. Atlassian confirmed the scrape.
Countries affected
- Global
07Data exposed
Data types
- Email Addresses
- Trello Usernames
- Public Profile Information
08Financial damage
No direct financial damage. Primarily risk of secondary attacks on affected users.
09Timeline
- 2024-07-15Dataset of 15M emails posted on BreachForums
- 2024-07-16Atlassian confirms scrape, implements rate limiting
10Reaction and fallout
Public reaction
Concern among Trello users about privacy and the ability to associate email addresses with project management data.
11Legal
Atlassian declined to change the API behavior, stating it was a planned feature for collaboration.
12Aftermath
Security improvements
- Atlassian added rate limiting to the affected API endpoint
13Significance and legacy
Significance
The Trello scrape demonstrated how legitimate API features designed for collaboration could be weaponized for bulk data collection, highlighting the privacy risks of email-to-account lookup functionality.
Legacy
Served as a case study for companies designing social/team features that expose email-to-account mappings, contributing to industry discussion about rate limiting and privacy-by-design.
14Disclosure and media
- Authentication
- Verification of sample data by multiple security researchers
Publishing organisations
- BleepingComputer
- HackRead
- CyberNews
15Field notes
- 01The attacker reportedly used a list of 500M email addresses compiled from other data breaches to query Trello's API.
- 02Trello's API was designed to allow team members to find each other by email - a feature that inadvertently enabled this large-scale scrape.
16Resolution
Atlassian implemented rate limiting on the GraphQL API endpoint. The underlying feature remained active as it was considered a core collaboration function.
17Sources
References
- [1]BleepingComputer
- [2]Atlassian official statement









