{"id":897,"date":"2024-10-24T10:46:28","date_gmt":"2024-10-24T16:46:28","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=897"},"modified":"2024-10-24T10:46:31","modified_gmt":"2024-10-24T16:46:31","slug":"trello-data-breach-precautionary-steps-for-affected-victims","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/10\/24\/trello-data-breach-precautionary-steps-for-affected-victims\/","title":{"rendered":"TRELLO DATA BREACH: PRECAUTIONARY STEPS FOR AFFECTED VICTIMS"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In other news, a popular project management tool from Atlassian, Trello, just experienced a serious data breach. According to reports from Hackread.com, the hacker whose alias is \u201cEmo\u201d recently leaked this data on a cybercrime platform called \u201cBreach Forums,\u201d where it was confirmed that a staggering 21.1GB of customer information was lost in this breach. [1]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers from Hackread.com confirmed that, according to the hacker, the data surfaced online on Tuesday, July 16, 2024, despite the breach occurring in January 2024. Some details that were captured in the breach include the following: [1]<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>User IDs<\/li>\n\n\n\n<li>Usernames<\/li>\n\n\n\n<li>Full names<\/li>\n\n\n\n<li>Profile URLs<\/li>\n\n\n\n<li>Status information<\/li>\n\n\n\n<li>Various settings and limits<\/li>\n\n\n\n<li>Associated board memberships<\/li>\n\n\n\n<li>Email addresses (15 million \u2013 15,182,073)<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-cover\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-background-dim\"><\/span><img decoding=\"async\" width=\"975\" height=\"616\" class=\"wp-block-cover__image-background wp-image-898 lazyload\" alt=\"\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-12.png\" data-object-fit=\"cover\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-12.png 975w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-12-300x190.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-12-768x485.png 768w\" data-sizes=\"(max-width: 975px) 100vw, 975px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 975px; --smush-placeholder-aspect-ratio: 975\/616;\" \/><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<p class=\"has-text-align-center has-large-font-size wp-block-paragraph\"><em>Source: hackread.com<\/em><\/p>\n<\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">What happened?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">According to &#8220;Emo,&#8221; his breach was allegedly successful due to an unsecured API in Trello\u2019s system. The said vulnerability (unsecured endpoint API) was accessible without user logins, thus accepting and allowing unauthorized access. [1] The endpoint API allowed \u201cEmo\u201d to link email addresses to Trello accounts, revealing user identities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Emo in the beginning only relied on emails from breached databases. He later went on full-scale to exploit the endpoint API with more and more emails, which eventually resulted in the magnitude of the breach we have now. Some of the uses of this leaked data could include: [1]<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Spam and phishing<\/li>\n\n\n\n<li>Credential stuffing<\/li>\n\n\n\n<li>Social engineering attacks<\/li>\n\n\n\n<li>Sold on the dark web<\/li>\n\n\n\n<li>Targeted advertisements<\/li>\n\n\n\n<li>Scams and extortions<\/li>\n\n\n\n<li>Identity theft<\/li>\n\n\n\n<li>Doxing<\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>Trello had an open API endpoint that allows any unauthenticated user to map an email address to a Trello account. I originally was only going to feed the endpoint emails from \u2018com\u2019 (OGU, RF, Breached, etc.) databases but I just decided to keep going with emails until I was bored. This database is very useful for doxing, find enclosed email address matched to full names and aliases matched to personal email addresses, The hacker said. [1]<\/em><\/p>\n<\/blockquote>\n<\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<div class=\"wp-block-cover\"><span aria-hidden=\"true\" class=\"wp-block-cover__background has-background-dim\"><\/span><img decoding=\"async\" width=\"975\" height=\"377\" class=\"wp-block-cover__image-background wp-image-899 lazyload\" alt=\"\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-13.png\" data-object-fit=\"cover\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-13.png 975w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-13-300x116.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/image-13-768x297.png 768w\" data-sizes=\"(max-width: 975px) 100vw, 975px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 975px; --smush-placeholder-aspect-ratio: 975\/377;\" \/><div class=\"wp-block-cover__inner-container is-layout-flow wp-block-cover-is-layout-flow\">\n<p class=\"has-text-align-center has-large-font-size wp-block-paragraph\"><em>Source: hackread.com<\/em><\/p>\n<\/div><\/div>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">User lessons for affected businesses and individuals.<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This leak highlights the imperative need for robust and reliable API security measures. Strong authentication, educating your team, authentication controls, limiting the amount of data the API exposes, constant monitoring, using API gateways to act as a middle layer between clients and backend services [3], and also monitoring for suspicious and malicious activities. [2] It is also important to stay updated with the best security practices by patching and updating regularly to ensure your systems do not get vulnerable due to out-of-date security patches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a Trello user, firstly, check if your data was compromised in the breach; you can do so by using https:\/\/nordpass.com\/have-i-been-hacked\/. [2] If the scan indicates you are safe, that\u2019s great. However, if it indicates otherwise, you will need to take some immediate action. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trello users should consider changing their emails and passwords to any account tied to the email affected by the leak. Also, set up multi-factor authentication. [2] Additionally, Trello users should be vigilant for phishing, as other cybercriminals may send you emails where they impersonate legitimate organizations offering juicy deals and unwanted help.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I\u2019d love to hear your thoughts! What advice would you give to victims in this situation? Do you agree with the recovery steps I mentioned, or do you see things differently? Please feel free to share any insights or experiences you\u2019ve had with similar data breaches. Your perspective would add to the conversation, and I\u2019m looking forward to hearing from you!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">References<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>&nbsp;<a href=\"https:\/\/hackread.com\/trello-data-breach-hacker-dumps-users-personal-info\/\">https:\/\/hackread.com\/trello-data-breach-hacker-dumps-users-personal-info\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/nordpass.com\/blog\/trello-data-breach\/\">https:\/\/nordpass.com\/blog\/trello-data-breach\/<\/a><\/li>\n\n\n\n<li>https:\/\/www.practical-devsecops.com\/api-gateway-security-best-practices\/#:~:text=An%20API%20Gateway%20serves%20as,the%20microservices%20in%20the%20backend.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In other news, a popular project management tool from Atlassian, Trello, just experienced a serious data breach. According to reports from Hackread.com, the hacker whose alias is \u201cEmo\u201d recently leaked this data on a cybercrime platform called \u201cBreach Forums,\u201d where it was confirmed that a staggering 21.1GB of customer information was lost in this breach. &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/10\/24\/trello-data-breach-precautionary-steps-for-affected-victims\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;TRELLO DATA BREACH: PRECAUTIONARY STEPS FOR AFFECTED VICTIMS&#8221;<\/span><\/a><\/p>\n","protected":false},"author":690,"featured_media":902,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-897","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","entry"],"featured_image_src":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/data-breach-600x400.jpg","featured_image_src_square":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/10\/data-breach-600x401.jpg","author_info":{"display_name":"Mohammed Idrisu","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/mohammed-idrisu\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/690"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=897"}],"version-history":[{"count":3,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/897\/revisions"}],"predecessor-version":[{"id":903,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/897\/revisions\/903"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media\/902"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}