Helpfeel breach exposes 23.62 million Gyazo user records and 490 million image metadata records
Helpfeel confirmed a Sept. 11 breach exposing 23.62 million Gyazo user records and 490 million image metadata records.
The breach happened on Sept. 11, when an unidentified threat actor abused a vulnerability to upload malware, gain access to the service's servers and run arbitrary commands on them, according to a breach notification published earlier this week. An investigation determined that 23.62 million records were compromised. Helpfeel said multiple records are tied to the same user and many were generated by customers without user accounts, so the actual number of affected individuals has not been determined but is definitely less than 23.6 million.
The compromised records include names, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with Google SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status without credit card numbers, and usage statistics. Helpfeel said it confirmed that no payment information, including credit card numbers, was disclosed without authorization.
Attackers also accessed image metadata. About 490 million records associated with images registered in or before January 2019 were compromised, including image IDs, the source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs and hashed passphrases for private images.
Because some of that metadata is used to generate image URLs, Helpfeel said it does not rule out the possibility that the attackers viewed actual images. It said it had temporarily disabled viewing of some images to prevent further harm and that, as it cannot rule out that some private images may have been viewed by the third party, it is continuing a detailed investigation.