Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Gyazo Data Breach. Show all posts

Gyazo Server Vulnerability Targeted to Steal Millions of User Records


Gyazo, an image-sharing platform, has confirmed a breach after attackers exploited a vulnerability in its upload server, gaining unauthorized access to the company's systems and approximately 23.62 million user records. 

Gyazo was developed by Japanese software company Helpfeel and allows users to upload images, GIFs, short videos and generate links for sharing. There are over 23 million users on the platform from 242 countries and regions, and billions of uploads have been processed. According to Helpfeel, the intrusion occurred on September 11, when a third party exploited a vulnerability in Gyazo's image upload server and became able to execute commands on the system as a result. 

On the same day, the company was notified of suspicious activity and began to investigate the incident. In the early hours of September 12, Helpfeel had blocked the access routes used for the attack and terminated any unauthorized connections. As part of the initial response, the exploited vulnerability was also fixed. However, an investigation revealed that the attacker was already able to access Gyazo's database and obtain user-related information. There are approximately 23.62 million records in the affected dataset. 

Depending on the account, information that will be exposed may include name or nickname, email address, password hashes, user and device IDs, login session IDs, profile information, subscription details, billing status and usage statistics. Additional information may be exposed if an account is linked to an external service. 

According to Helpfeel, integration tokens for accounts connected to X may be included, while Google SSO email addresses may also be included for users who signed in through Google. In a statement issued by the company, it clarified that payment information, including credit card numbers, was not exposed. 

The affected records also include anonymous accounts without registered email addresses, therefore it is not yet known how many people will be affected. The incident involved not only account information, but also a much larger collection of image-related metadata. According to Helpfeel, approximately 490 million metadata records were disclosed, primarily those associated with images uploaded before January 2019. It is possible for an image ID to be exposed, as well as IP addresses and User Agent details, EXIF location information, OCR-extracted text, image titles, and source URLs. 

A separate privacy concern arises from the image metadata, as Gyazo uses image IDs to generate URLs for uploaded captures. According to Helpfeel, the stolen IDs may allow access to some images, so the company temporarily disabled access to affected files while investigating. As a result, approximately 490 million images have been compromised, most of which were uploaded in January 2019 or earlier. 

Information may include image IDs, IP addresses, User-Agent strings, EXIF location information, OCR-extracted text, title of the image, and URL of the source. Besides the data exposed, Helpfeel also identified a separate set of approximately 2.4 million image records which were retrieved according to specific filtering criteria, including hacked passphrases associated with private images. This company has not provided information on the criteria used or clarified whether the records overlap with the larger metadata set. Also exposed in the incident was a list of private images. 

Helpfeel did not exclude the possibility that private pictures were viewed by the attacker. The number of private images accessed has not been determined by the company. Because Gyazo handles image privacy in a very sensitive manner, the disclosure of image IDs is particularly significant. The URL of each capture includes a 32-character ID, and older captures can still be accessed through their original URLs even after they are not prominently displayed within a user's account. 

The leaked identifiers therefore could be used to gain access to content that was not intended to be viewed by the general public. By the early hours of September 12, Helpfeel detected suspicious activity and blocked the identified access routes, terminating the attacker's connections. The exploited server vulnerability was immediately addressed. 

In September 14, the company confirmed the data exposure and reported the incident to the Japanese Personal Information Protection Commission. During the course of the investigation, Gyazo temporarily suspended image delivery. A forensic investigation is currently underway by Helpfeel, and affected users will be contacted directly. 

Anonymous accounts will be handled by Gyazo through notifications posted on the website. Despite finding no evidence of the deletion of image data during the incident, the company has not identified a data leak involving its separate Helpfeel and Cosense services. Users have been advised to change their Gyazo passwords and avoid reusing the same credentials on other services in light of the exposed authentication data. 

Helpfeel has also taken action to invalidate or restrict the affected credentials and authentication information. Furthermore, the company has cautioned against the possibility of exploitation of information disclosed in the breach through suspicious emails and messages.