AI & TechBigTech CompaniesCybersecurityNewswireTechnology

Gyazo Breach: 23.6M User Records Stolen via Server Flaw

▼ Summary

– Japanese software company Helpfeel confirmed a data breach on its screenshot-sharing platform Gyazo where attackers exploited an image upload server vulnerability.
– The incident resulted in the unauthorized access of approximately 23.62 million user records and metadata linked to hundreds of millions of images.
– Stolen data includes names, email addresses, password hashes, and device IDs, though no payment information was compromised.
– Helpfeel has blocked the attacker’s access, reported the incident to Japanese authorities, and is notifying affected users via email and web interface.
– Users are advised to change their passwords immediately as investigators continue to determine if private images were viewed.

Critical Vulnerability Exposes Millions of Gyazo Users

Japanese technology firm Helpfeel has officially acknowledged a severe data breach affecting its popular screenshot-sharing service, Gyazo. The incident involved attackers leveraging a critical flaw in the platform’s image upload server to exfiltrate approximately 23.62 million user records. Alongside personal account data, the breach compromised metadata linked to hundreds of millions of images stored on the cloud-based platform.

Gyazo operates as a utility for capturing and sharing screen recordings and screenshots, automatically generating shareable links for use across social media and messaging platforms. The security failure occurred on September 11, when an unauthorized actor exploited the system vulnerability to execute arbitrary commands within Gyazo’s infrastructure. Helpfeel’s security team identified the suspicious activity later that evening. By the early morning of September 12, the company had successfully blocked the intrusion vectors and severed the attacker’s connections.

Scope of Compromised Data and Metadata

The investigation revealed that the intruder accessed the core database, leading to the unauthorized disclosure of sensitive user information. The stolen dataset contains a wide array of identifiers and authentication details.

“Our subsequent investigation confirmed that the third party had accessed Gyazo’s database and that user information and metadata associated with uploaded images had been disclosed without authorization,” the company stated in its official report.

The compromised user records encompass names, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile information, language preferences, registration and login timestamps, subscription plans, and billing status. Despite the breadth of the exposure, Helpfeel emphasized that financial data remained secure.

“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization.”

Beyond individual accounts, the scope of the data theft extended significantly into image metadata. Approximately 490 million metadata records were accessed, primarily comprising images uploaded in or before January 2019. This represents roughly 14.4% of all image data hosted on the platform. Additionally, hackers utilized specific filtering techniques to extract metadata from another 2.4 million images. This secondary batch included image IDs, upload IP addresses, user agents, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases used to protect private files.

Privacy Concerns and Ongoing Investigation

A particularly alarming aspect of the breach is the potential exposure of private content. The attackers obtained a comprehensive list identifying which images were designated as private by users.

“We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation,” the company added.

Helpfeel noted that there is currently no evidence suggesting data was breached from its other services, Helpfeel and Cosense. However, because Gyazo paused image delivery to contain the threat, some images embedded in those other tools may remain temporarily unavailable.

User Remediation and Service Status

Helpfeel reported the incident to Japan’s Personal Information Protection Commission on September 15. The company is now initiating notification procedures, sending emails to registered users and displaying alerts via the Gyazo web interface for anonymous accounts lacking registered email addresses.

In light of the compromise, Helpfeel issued urgent guidance to its user base regarding account security.

“We ask all Gyazo users to change their passwords,” the notice reads, extending the same advice to any other account sharing the same or a similar password.

The company expressed regret for the disruption caused by the attack.

“We sincerely apologize to all Gyazo users and other affected parties for the significant concern and inconvenience caused by this incident,” Helpfeel wrote.

As of the latest update, Gyazo’s homepage displays a maintenance notice indicating that the service remains offline. The company has not yet provided a timeline for when full functionality will be restored.

(Source: Help Net Security)

Topics

data breach incident 98% user data exposure 92% image metadata theft 88% incident response actions 85% security recommendations 80%
Show More