Gyazo data breach leaks image IDs and 23.62 million records
AI-generated image

Gyazo data breach leaks image IDs and 23.62 million records

Helpfeel says a flaw in Gyazo's upload server exposed 23.62 million user records and 490 million image metadata entries, including image link IDs.

The Gyazo data breach disclosed by the Kyoto based company Helpfeel exposed about 23.62 million user records and roughly 490 million image metadata records, the screenshot and image sharing service says. Helpfeel published its notice on Wednesday. The leaked user records can include email addresses and password hashes, which are scrambled versions of passwords stored so that the original password is not kept in readable form. The image records include the identifiers that make up Gyazo image links, and Helpfeel says those identifiers could be used to view images without permission.

The intrusion itself was carried out through a vulnerability in Gyazo's image upload server, according to Helpfeel. The attacker used that flaw to run arbitrary commands on the company's systems, meaning code chosen by the attacker rather than by Helpfeel, and reached the Gyazo database. Helpfeel has not said what kind of flaw it was. The company says no payment information, including credit card numbers, was exposed.

Helpfeel says it noticed suspicious activity on the evening of September 11, Japan time. By the early hours of September 12 it had blocked the access routes it had identified, cut the attacker's connections and fixed the vulnerability, all within the same day. It confirmed on September 14 that data had been exposed, reported the incident to Japan's Personal Information Protection Commission on September 15 and published its notice on September 16.

About the 23.62 million figure, Helpfeel says it counts records rather than people, that the total includes anonymous accounts with no registered email address, and that the company is still working out how many individuals had personal information exposed. The fields present vary from user to user. According to Helpfeel's list, an exposed user record can contain a display name (any text the user entered, such as a name or nickname), an email address, a password hash, a user ID, a device ID, a login session ID, an X (formerly Twitter) integration token if the account was connected, the email address used for Google single sign-on if connected, profile information, language preference, registration date and time, last login date and time, subscription plan, billing status (with no credit card numbers or other payment details) and usage statistics.

Two of those terms are worth spelling out. A login session ID is the code a website gives your browser after you sign in so that it recognises you on your next click, and anyone holding it may be able to act as you without a password. Single sign-on, or SSO, is a login method where one account, in this case a Google account, is used to sign in to another service. Helpfeel says it reviewed the exposed authentication data and took "the necessary measures, including invalidation and restrictions", but it has not said which items were invalidated. Gyazo normally emails a verification code when a login comes from a new IP address, a check that runs at login, and Helpfeel has not said whether the exposed session IDs remain valid.

The image side of the breach is where the practical risk for users lies. Every Gyazo capture gets a link built from a 32 character image ID. Gyazo's help pages say a capture stays private until its link is shared, that anyone who has the link can see it, and that the ID is long enough that a link "can't be guessed". For a capture at the default setting, the link is the only thing protecting it, and the leaked image IDs are exactly the part of the link that makes it unguessable. Free accounts can browse only their 10 most recent captures on Gyazo's site, but Gyazo says older captures are not deleted and remain accessible to anyone with the URL.

Helpfeel says the affected metadata records are mostly for images registered in January 2019 or earlier and make up about 14.4% of the company's image related data. Metadata is information about a file rather than the picture itself. A further 2.4 million images had their metadata pulled separately using what Helpfeel calls "specific filtering criteria". The company has not said what that filter was, whether the two sets overlap, or whether the second set includes newer images. The metadata fields Helpfeel lists include the image ID used to build the image URL, the IP address used for the upload, the User Agent (the text that identifies the browser or app used), EXIF location data if the image contained it, OCR text extracted from the image, image title, source URL and other metadata, and a hashed passphrase for private images. EXIF is the hidden information cameras and phones attach to a photo, which can include where it was taken. OCR stands for optical character recognition, the process of reading text out of a picture. That OCR text comes from a Gyazo feature that reads the text in a user's captures so they can be searched; Gyazo's help pages describe it as a paid feature that users enable themselves, that then scans all the account's images, and state that "Only you can see OCR results".

Helpfeel also says the attacker obtained a list identifying private images, and that the company "cannot rule out the possibility that the third party may have viewed some private images". On Gyazo, a private capture can mean one set to "Only me", which the help pages say cannot be viewed even by someone who knows the link, or one locked with a password. Both settings are available only on paid plans, and Helpfeel has not said which it means or how such images could have been viewed. The company says it temporarily disabled viewing of some images to prevent further harm and that its investigation has not found any loss of image data, but it has not said which images are disabled or how a user can tell whether their captures are in the affected sets.

There is also a question about how the Gyazo data breach was communicated while it was unfolding. While images were failing to load, Gyazo's public notices to users called it maintenance and did not mention a breach. When Helpfeel suspended image delivery on September 14, Gyazo's product updates page said delivery had been suspended for some images "due to emergency maintenance". After delivery of new uploads resumed on September 15, a second notice said, "Some images remain unavailable due to emergency maintenance."

Helpfeel is asking every Gyazo user to change their password, and to change it on any other service where the same or a similar password is used, and to watch for suspicious emails or messages related to the incident. Outside specialists are now running a forensic investigation, the company says, and it will email users it identifies as affected, with notices on Gyazo's website for anonymous accounts. It is taking questions about the incident through Gyazo's support form. Helpfeel's other products, Helpfeel and Cosense, run on separate systems, and the company says it has not found any data exposure from them, though Gyazo images shown inside them may not load while image deliv

How to Protect Yourself

  1. Change your Gyazo password today, and if you used that same password anywhere else, change it on those sites too, because one stolen password can unlock several accounts.
  2. Turn on two step verification wherever it is offered, which means the site asks for a short code from your phone as well as your password when you log in.
  3. Ignore emails or messages that ask you to click a link and enter your Gyazo password, and instead go to gyazo.com by typing the address yourself.
  4. Review the screenshots and images you have stored in Gyazo, especially older ones and anything private, and delete or lock the ones you would not want a stranger to see.
  5. If you sent someone a Gyazo link to a private image, treat that link as no longer secret and remove or replace the image.
  6. Keep the software you use up to date, since attackers usually get in through flaws that the maker has already fixed in a newer version.

Terms Explained

  • password hash A scrambled form of your password that a website stores instead of the password itself, so that nobody reading the file can see your real password.
  • metadata Extra information stored alongside a file, such as when an image was uploaded or which device sent it, rather than the picture you actually see.
  • EXIF Hidden details that cameras and phones attach to a photo, which can include the exact place and time the picture was taken.
  • OCR Short for optical character recognition, the process a computer uses to read text that appears inside a picture.
  • session ID The code a website gives your browser after you log in so it knows it is still you, and which can let someone else act as you if it is stolen.
  • single sign-on A way of logging in where one account, such as a Google account, is used to sign in to other services without a separate password.
  • User Agent The piece of text your browser or phone app sends to a website to say which browser and device you are using.
  • vulnerability A weakness or mistake in software that an attacker can use to get into a system they are not supposed to reach.

Related AEU services

  • AEU-I IT and security consulting