Post

Gyazo Data Breach Exposes 23 Million User Records

Gyazo Data Breach Exposes 23 Million User Records

Gyazo Data Breach Exposes 23 Million User Records 🚨

A recent breach involving Gyazo has exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Helpfeel confirmed that approximately 23.62 million records containing data related to Gyazo users were disclosed without authorization.

The breach occurred on September 11, when the threat actor exploited a vulnerability in the image upload server, allowing them to run malicious commands. Although the attacker was locked out the following day, they had already accessed a database containing about 23.6 million user records.

What Was Exposed? 📊

The stolen data includes:

  • Names
  • Email addresses
  • Password hashes
  • User and device IDs
  • X integration tokens
  • Profile details
  • Usage statistics
  • Billing information

Helpfeel stated that payment card data was not affected. They confirmed that the exposed data may include various identifiers and metadata associated with uploaded images. Notably, the affected records also include anonymous accounts without registered email addresses.

Additionally, about 490 million image metadata records were exposed, mainly linked to images uploaded in or before January 2019. This metadata could potentially be used to reconstruct Gyazo image URLs and access images without authorization.

Company Response 🔒

Helpfeel has temporarily disabled access to some images and confirmed that a list of private images was obtained. They have blocked all access routes used in the incident and completed remediation of the exploited vulnerability. The company is prioritizing measures to prevent further harm while investigating the scope and impact of the incident.

They plan to send notifications regarding this incident to the registered email addresses of affected Gyazo users. For users without registered email addresses, notifications will be provided through the Gyazo web interface. Users are advised to change their passwords and remain vigilant for suspicious communications.

The investigation is ongoing, and further updates will be published as more information emerges.

Read full article

This post is licensed under CC BY 4.0 by the author.