news.mlab.sh
Back to the feed
data-breach

23 Million User Records Compromised in Gyazo Data Breach

Medium
Summary

A Japanese image-sharing service, Gyazo, suffered a data breach exposing the personal information of approximately 23.6 million users. The attackers exploited a vulnerability to gain access to user data, including names, email addresses, and password hashes. While payment card details were not compromised, the incident highlights the risks associated with image-sharing platforms and the potential for attackers to reconstruct image URLs.

Gyazo, a popular cross-platform image-sharing tool, has been affected by a significant data breach. Helpfeel, the Japanese software company behind Gyazo, announced that hackers gained unauthorized access to its servers on September 11th. The attackers exploited a vulnerability within Gyazo’s image upload server, allowing them to execute malicious commands.

Following the initial breach, the attacker was removed from the system the next day, but not before accessing a database containing roughly 23.62 million user records. This data included sensitive information such as names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, and billing details. Notably, payment card information was not compromised in this incident.

Furthermore, the attacker also accessed approximately 490 million image metadata records. This metadata could be used by threat actors to reconstruct and access URLs associated with images uploaded by users. The company has not yet disclosed the volume of private images that were compromised.

Helpfeel is continuing to investigate the scope of the breach and determine the exact number of individuals whose personal information was disclosed without authorization. The incident underscores the importance of robust security practices for image-sharing services and the potential consequences of exploiting vulnerabilities.

Read the full article at SecurityWeek