Japanese software firm Helpfeel has alerted users of its popular image-sharing platform, Gyazo, about a significant security breach. The breach allowed unauthorized access to sensitive user information.
Unauthorized Access to Gyazo Servers
Gyazo, a versatile tool used across multiple platforms, enables users to capture and share screenshots, GIFs, and short videos. Recently, Helpfeel discovered a security loophole in their image upload server, which was exploited by a hacker on September 11.
The malicious actor managed to execute unauthorized commands, gaining access to the servers. Although the breach was contained within a day, the attacker accessed a substantial user database.
Details of Compromised User Information
The breach affected approximately 23.6 million user records, which included names, email addresses, password hashes, user IDs, device IDs, integration tokens, profile data, and usage statistics. Fortunately, payment card information remained secure.
Helpfeel noted that the affected records also covered anonymous accounts without registered email addresses, and they are currently assessing the exact number of individuals impacted by this unauthorized disclosure.
Impact on Image Metadata and Private Images
In addition to user data, the attacker accessed about 490 million image metadata records. This metadata could potentially be used to trace and access URLs of images uploaded by users.
The breach also involved a list of private images, though Helpfeel has yet to disclose the volume of these compromised images. The incident highlights the need for enhanced security measures to protect user privacy on such platforms.
In light of this event, users are advised to remain vigilant and update their security settings as necessary. Helpfeel continues to investigate the breach to prevent future occurrences and safeguard user data.
