Gyazo Data Breach: 23.6 Million User Records Exposed via Server Vulnerability

www.news4hackers.com-gyazo-data-breach-23-6-million-user-records-exposed-via-server-vulnerability-gyazo-data-breach-23-6-million-user-records-exposed-via-server-vulnerability

Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.

Overview of the Data Breach

Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.

About Gyazo

Gyazo is a cloud-based screenshot and screen-recording service that uploads users captures automatically and generates a shareable link they can post in chats, forums, or social media.

Timeline of the Incident

According to the company, an attacker exploited the vulnerability on September 11 to gain unauthorized access to Gyazo’s systems and run arbitrary commands. Suspicious activity was detected that same evening, and by the early hours of September 12, the access routes had been blocked and the attacker’s connections cut off.

Company Statement on the Breach

“Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization,” the company said.

Details of the Stolen User Records

Based on its investigation, the company found that the stolen user records, around 23.62 million of them, include names, addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens for connected accounts, Google SSO addresses, profile information, language preferences, registration and login timestamps, subscription plans, and billing status.

Payment Information Not Compromised

“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization.”

Image Metadata Exposed

The image metadata is larger in scope, approximately 490 million records, tied mostly to images uploaded in or before January 2019, about 14.4% of all image data on the platform. An additional 2.4 million images were separately pulled through specific filtering.

Details of the Image Metadata

This metadata included image IDs used to build image URLs, upload IP addresses, user agents, EXIF location data where present, OCR text extracted from images, image titles, source URLs, and hashed passphrases protecting private images.

Private Images Possibly Accessed

“We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation,” it added.

Investigation of Other Services

The company also said its investigation has found no sign that data was taken from its other two services, Helpfeel and Cosense. Some images embedded in those tools through Gyazo may still be unavailable, since Gyazo paused image delivery in response to the incident.

Notification to Authorities

Helpfeel reported the incident to Japan’s Personal Information Protection Commission on September 15.

User Advice and Next Steps

We ask all Gyazo users to change their passwords, the notice reads, extending the same advice to any other account sharing the same or a similar password. We sincerely apologize to all Gyazo users and other affected parties for the significant concern and inconvenience caused by this incident, Helpfeel wrote.

Current Status of Gyazo

At the time of writing, Gyazo’s homepage still shows a maintenance notice, with no timeline given for when the service will return.



About Author

en_USEnglish