2024 Trello — 15.1M emails via misconfigured API
Data compromised
Email addresses linked to usernames and account info
Technical writeup
Trello (Atlassian) suffered a data exposure in 2024 when researchers discovered that a misconfigured API could be abused to link email addresses to 15 million Trello accounts. The API allowed enumeration of user data without proper authentication.
Root cause
Misconfigured API; insufficient access controls