Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack
A vulnerability in an image sharing service resulted in millions of records being exposed
- Helpfeel confirmed a Sept 11 breach compromising 23.62M records tied to Gyazo users
- Stolen data includes PII, login/session IDs, Google SSO tokens, and 490M image metadata records
- Payment info safe, but private images may have been exposed; viewing disabled pending investigation
A Japanese customer-support and knowledge-base company suffered a cyberattack recently in which it lost millions of user records, including personally identifiable information (PII) and, possibly, customer photographs.
The company in question is called Helpfeel. It is an established organization with more than 200 employees, operating as a combination of a modern help center, intelligent search, and an AI support agent. It runs an image-sharing service called Gyazo. According to a breach notification published earlier this week, the breach happened on September 11, when an unidentified threat actor abused a vulnerability to upload malware, gain access to the service’s servers, and run arbitrary commands on them.
A subsequent investigation determined that the attacker compromised 23.62 million records. Multiple records are tied to the same user, and many of the records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined (but it’s definitely less than 23.6 million).
Image metadata exposed, too
The compromised records fall into these categories: names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with Google SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics.
“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization,” Helpfeel confirmed.
PII aside, the attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including image IDs, source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.
Since some of this metadata is used to generate image URLs, Helpfeel does not rule out the possibility that the attackers viewed actual images, as well. “We have temporarily disabled viewing of some images to prevent further harm,” it said. “As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via The Hacker News
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.