← Atlassian

2024 Trello — 15.1M emails via misconfigured API

2024 15.1M records affected Share on X

Data compromised

Email addresses linked to usernames and account info

Technical writeup

Trello (Atlassian) suffered a data exposure in 2024 when researchers discovered that a misconfigured API could be abused to link email addresses to 15 million Trello accounts. The API allowed enumeration of user data without proper authentication.

Root cause

Misconfigured API; insufficient access controls

References