FYI - got a notification about this this morning - just wanted to pass it along
In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred.
As the Article suggests, no email addresses or names were directly obtained from Trello, only the public bio page was accessed. If it so happens that your email was matched to your Trello username, you may want to ensure that your email address is better protected.
The article sets out the steps you can take to protect yourself:
Enable two-factor authentication on your Trello account.
Use a strong unique password mixing letter, numbers, and special characters.
You can also use a password manager such as LastPass or Bitwarden to generate and manage your account’s password.
Hey there, John!
We shared more about this here: https://community.atlassian.com/t5/Trello-articles/Setting-the-record-straight-about-Trello-user-profile-data/ba-p/2587253
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.