Gyazo is the tool you reach for when you want to throw a screenshot at somebody in one keystroke. Helpfeel, the Japanese company that runs it, now says an attacker reached the service's database and left with roughly 23.62 million user records, along with metadata describing hundreds of millions of the images people uploaded.
Some of that metadata can be used to open the pictures.
Detected in the evening, cut off by dawn
In its notice of 16 September, Helpfeel says the intruder exploited a vulnerability in Gyazo's image upload server, ran arbitrary commands on company systems, and from there reached the Gyazo database. The company detected unusual activity on the evening of 11 September Japan time and, by the early hours of 12 September, had blocked the entry routes it had identified, cut the attacker's connections and fixed the underlying flaw. It confirmed the data loss on 14 September and suspended image delivery, added further protections and filed a report with Japan's Personal Information Protection Commission on 15 September, then published the notice a day later.
Screenshots remember more than people expect
The user records cover names, email addresses, password hashes, user IDs, device IDs, login session IDs, single sign-on tokens, profile data, language settings, registration and login dates, subscription plans and billing status. Credit card numbers and other payment details were not exposed, and Helpfeel says its Helpfeel and Cosense products were unaffected.
The image side is the part worth sitting with. Around 490 million metadata records covering images registered up to January 2019 went out, plus about 2.4 million images retrieved using specific filters. That metadata includes image IDs, source IP addresses, EXIF location data, image titles, the OCR text Gyazo extracts from each screenshot, and hashed passphrases for private images. A screenshot is whatever happened to be on somebody's monitor at the time, and the OCR field is a machine-readable transcript of it. Helpfeel states plainly that the metadata could be used by a third party to access and view the corresponding images without authorization, which is why image delivery went down while it responded.
Change the password, and everywhere it was reused
Helpfeel is asking every Gyazo user to change their password, and to change it on any other service where the same or a similar one is in use. With login session IDs and single sign-on tokens in the exposed set, signing out of active sessions everywhere is a sensible companion step.
The breach lands in a bad month for Japanese organizations. A government VPN appliance compromise showed that patching an edge device is not the end of the job, August brought a run of hacktivist DDoS alongside genuine intrusions, and Japan's wider threat picture has stayed busy all quarter. Check Point Research's weekly bulletin, which picked the Gyazo case up on 21 September, listed it alongside three other fresh breaches from the same seven days.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.