- Helpfeel confirmed a Sept 11 breach compromising 23.62M records tied to Gyazo users
- Stolen data includes PII, login/session IDs, Google SSO tokens, and 490M image metadata records
- Payment info safe, but private images may have been exposed; viewing disabled pending investigation
A Japanese customer-support and knowledge-base company suffered a cyberattack recently in which it lost millions of user records, including personally identifiable information (PII) and, possibly, customer photographs.
The company in question is called Helpfeel. It is an established organization with more than 200 employees, operating as a combination of a modern help center, intelligent search, and an AI support agent. It runs an image-sharing service called Gyazo. According to a breach notification published earlier this week, the breach happened on September 11, when an unidentified threat actor abused a vulnerability to upload malware, gain access to the service’s servers, and run arbitrary commands on them.
A subsequent investigation determined that the attacker compromised 23.62 million records. Multiple records are tied to the same user, and many of the records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined (but it’s definitely less than 23.6 million).
Image metadata exposed, too
The compromised records fall into these categories: names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with Google SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics.
“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization,” Helpfeel confirmed.
PII aside, the attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including image IDs,ata, OCR text extracted from the images, image titles
Since some of this metadata is used to generate image URLs, Helpfeel does not rule out the possibility that the attackers viewed actual images, as well. “We have temporarily disabled viewing of some images to prevent further harm,” it said. “As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”
