Gyazo breach exposes 23.62 million user records and 490 million image records β€” PII and metadata exposed in huge attack
TechRadar

Gyazo breach exposes 23.62 million user records and 490 million image records - PII and metadata exposed in huge attack

Background

Helpfeel, a Japanese customer-support and knowledge-base company with more than 200 employees, operates the image-sharing service Gyazo. The company provides a modern help center, intelligent search, and an AI support agent.

On September 11, an unidentified threat actor abused a vulnerability to upload malware, gain access to the service’s servers, and run arbitrary commands. Helpfeel confirmed the breach in a notification published earlier this week.

Scope

The attacker compromised 23.62 million records. Multiple records are tied to the same user, and many records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined but is definitely less than 23.6 million.

Exposed Data

The compromised user records include:

  • names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with Google SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics.

β€œWe have confirmed that no payment information, including credit card numbers, was disclosed without authorization,” Helpfeel confirmed.

Image Metadata

Attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including:

  • image IDs, source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.

Since some metadata is used to generate image URLs, Helpfeel does not rule out that attackers viewed actual images. β€œWe have temporarily disabled viewing of some images to prevent further harm,” it said. β€œAs we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”

Source

Via The Hacker News

Author

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read on TechRadar ↗ ← Back to News

Comments

No comments yet. Start the discussion.