Desk live·
ForensicPost
Breaches/API/File 24-0123

Trello Profile Data for 15 Million Users Scraped Through a Public API

A public Trello endpoint would confirm whether an email address belonged to an account and return the profile attached to it. Someone fed it a list and offered 15 million records for sale.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTrello
ActorUnattributed
S. Rosler8 min readConfidence: high2 sources reviewed

Records covering around 15 million Trello users were listed for sale on a criminal forum in January 2024. The data pairs email addresses with the public profile attached to each account — names, usernames and related profile fields.

Atlassian, which owns Trello, said there was no unauthorised access to its systems. A public API endpoint accepted an email address and returned the matching public profile, so a list of addresses obtained elsewhere could be turned into a list of confirmed accounts. The company subsequently required authentication to query profile information that way.

Nothing Was Breached, Which Is The Point

Every record returned was public by design. What the endpoint added was confirmation: it told the caller which addresses in a bought list were real Trello users, and attached a name to each one.

That turns a generic address dump into a targeted one. A phishing message that names the recipient and the product they use performs very differently from one that does not, and the company whose API supplied the pairing has suffered no intrusion to report.

Rate Limiting Is The Control That Was Missing

An endpoint answering one query at a time is a feature. The same endpoint answering fifteen million is a bulk export, and the only thing separating the two is a limit nobody set.

We have recorded the same pattern at Optus in 2022 and T-Mobile in 2023, both unauthenticated interfaces answering at volume. Where no credential is required there is no failed login to alert on, so the query count is the only signal available.

How we reported this

Compiled from public reporting and Atlassian’s statements, listed below. The 15 million figure originates with the seller and has not been confirmed by the company. Corrections: corrections@forensicpost.com.

Sources
  1. Email addresses of 15 million Trello users leaked on hacking forumBleepingComputer
  2. Personal Details Of 15 Million Trello Users Up For SaleForbes
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary