I just got the email from haveibeenpwned. F Trello.

    • Albatross2724@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      8 months ago

      For project tools like Trello, a good portion of your userbase is company emails. A malicious actor now has a list of company emails that they can compare against public facing data like Linkedin, imitate a user using a gmail based off their name, sending an email to that company’s IT team asking for an MFA reset sent to the newly created gmail account. Now imagine if that compromised user is a developer with admin access to production environments. These were the conditions for various ransomware attacks.

      An email, username, real name are not much, but it’s a foot in the door.