23 Million User Records Compromised in Gyazo Data Breach
Hacker exploited a Gyazo upload-server flaw, exposing 23.6 million user records and 490 million image metadata records.
Helpfeel disclosed that a hacker exploited a vulnerability in Gyazo's image upload server on September 11, executing malicious commands before being removed the next day. The attacker accessed a database with roughly 23.62 million user records, including names, email addresses, password hashes, user and device IDs, X integration tokens, profile data, usage statistics, and billing information. Additionally, about 490 million image metadata records were accessed, potentially allowing reconstruction of URLs to users' uploaded images, and a list of private images was also compromised. Payment card data was not affected.
- Hacker exploited a flaw in Gyazo's image upload server on September 11, executing commands
- 23.62 million records exposed: names, emails, password hashes, device IDs, X tokens
- 490 million image metadata records accessed, potentially exposing private image URLs
- Payment card information not compromised; affected individual count still being determined
Full article258 words · extracted from securityweek.com · click to collapse
Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information.
Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.
Helpfeel revealed this week that it recently detected unauthorized access to Gyazo servers. A hacker exploited a vulnerability in its image upload server on September 11, enabling them to execute malicious commands.
The attacker was kicked out the next day, but not before accessing a database storing roughly 23.6 million user records.
The compromised Gyazo user information includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information.
Payment card information was not compromised, according to the vendor.
Advertisement. Scroll to continue reading.
“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” Helpfeel said.
In addition to the user records, the attacker accessed roughly 490 million image metadata records. This metadata includes information that could allow threat actors to reconstruct and access URLs associated with images uploaded by users.
A list of private images has also been compromised, but the company has not shared any information on volume.
Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: 280,000 Impacted by Premier Medical Group Data Breach
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/23-million-user-records-compromised-in-gyazo-data-breach/