Gyazo breach exposes 23.62 million user records and 490 million image records - PII and metadata exposed in huge attack
Background
Helpfeel, a Japanese customer-support and knowledge-base company with more than 200 employees, operates the image-sharing service Gyazo. The company provides a modern help center, intelligent search, and an AI support agent.
On September 11, an unidentified threat actor abused a vulnerability to upload malware, gain access to the serviceβs servers, and run arbitrary commands. Helpfeel confirmed the breach in a notification published earlier this week.
Scope
The attacker compromised 23.62 million records. Multiple records are tied to the same user, and many records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined but is definitely less than 23.6 million.
Exposed Data
The compromised user records include:
- names, emails, password hashes, user IDs, device IDs, login session IDs,
Xintegration tokens, email addresses associated withGoogle SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics.
βWe have confirmed that no payment information, including credit card numbers, was disclosed without authorization,β Helpfeel confirmed.
Image Metadata
Attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including:
- image IDs, source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.
Since some metadata is used to generate image URLs, Helpfeel does not rule out that attackers viewed actual images. βWe have temporarily disabled viewing of some images to prevent further harm,β it said. βAs we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.β
Source
Via The Hacker News
Author
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, heβs written for numerous media outlets, including Al Jazeera Balkans. Heβs also held several modules on content writing for Represent Communications.
Comments
No comments yet. Start the discussion.