Almost a million Trello boards, thousands of which contain corporate data of large and small Russian companies, were publicly available.
Alexey Parfentiev, leading analyst at SearchInform: “Scammers can use data from the boards to attack company customers or hack corporate Instagram accounts - last fall there was a surge”.
For now, Trello is one of the most popular task managers in Russia - it is used both by SMB segment and by large organizations, including banks.
On Trello boards organizations used to post:
Such negligence resulted in more than 9 thousand boards featuring highly sensitive information being publicly available.
Default settings presuppose restricted access; however, for their convenience users change them to public ones. In this case, the boards start being indexed by search engines.
Open-board-problem is not a new phenomenon. Thus, in 2017, Trello boards exposed data from Rostelecom (Russia's
leading long-distance telephony provider.), Acronis (global technology company), and MTS (the largest mobile network
operator in Russia) In 2018, KrebsOnSecurity
also reported a leak from ride-hailing service Uber.
Alexey Parfentiev, leading analyst at SearchInform:
For exposing employee and customer confidential data companies may face fines under the Personal Data Protection
Act. In February 2021, the State Duma passed a bill to increase the fines for violating the law on Personal
Data.
For now, the main recommendation for Russian companies is to switch to paid online project managers or avoid posting confidential corporate information in Trello.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!