JAPANESE software company Helpfeel has warned Gyazo users that hackers accessed the image-sharing service’s servers. The attacker exploited a vulnerability in Gyazo’s image-upload server on 11 September, allowing malicious commands to be executed, according to Helpfeel. The company removed the attacker the following day, but the intruder had accessed a database containing approximately 23.62 million user records.
The exposed information may include names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information. Helpfeel said payment-card data was not compromised. The total includes anonymous accounts without a registered email address, and the company is still determining how many individuals had personal information disclosed.
The breach also involved roughly 490 million image-metadata records, some of which could help attackers reconstruct or access URLs linked to uploaded images. A list of private images was accessed, although Helpfeel has not disclosed its size.