In a significant data breach, Gyazo, the image-sharing platform operated by Helpfeel, revealed that approximately 23.62 million user records were compromised. This breach also included a staggering 490 million image metadata records. Helpfeel, based in Kyoto, disclosed the incident and advised users on precautionary measures.
User Data and Image Metadata Compromised
The breach exposed sensitive user data, such as email addresses and password hashes, along with image metadata primarily from January 2019 and earlier. These metadata records include unique IDs, allowing unauthorized access to images without user consent. Consequently, Helpfeel has temporarily restricted viewing of certain images to prevent further unauthorized access.
Helpfeel urged Gyazo users to update their passwords immediately and be vigilant against suspicious communications. The breach was made possible through a vulnerability in Gyazo’s image upload server, which allowed the attacker to execute unauthorized commands and access the database. However, financial information, such as credit card details, remained secure.
Details of the Data Breach
A variety of user data fields were potentially exposed, although not all users are affected in the same way. The exposed data includes names, email addresses, user IDs, and session IDs, among others. In certain cases, integration tokens for services like X (formerly Twitter) and Google single sign-on details were also accessed. Despite the large number of records involved, the exact number of individuals affected is still being determined by Helpfeel.
In response, Helpfeel has taken steps to review and invalidate compromised authentication data. However, it remains unclear which specific data items were invalidated. The breach also affected image metadata, with records for images captured before January 2019 accounting for a significant portion of the affected data.
Response and Future Measures
Following the detection of suspicious activities on the night of September 11, Helpfeel swiftly addressed the security flaw by blocking access routes and severing the attacker’s connections. While the breach temporarily disrupted image loading, Helpfeel initially attributed it to maintenance without disclosing the breach.
By September 14, Helpfeel confirmed the data exposure and reported the incident to Japan’s Personal Information Protection Commission. A public notice followed, with assurances that external experts are conducting a forensic investigation. Users identified as affected will be notified via email, with updates for anonymous accounts posted on Gyazo’s website. Helpfeel has emphasized that its other services remain unaffected by the breach.
The incident highlights the importance of robust cybersecurity measures and user vigilance in safeguarding personal information online. As investigations continue, users are encouraged to remain proactive in securing their accounts and monitoring any unusual activities.
