SHINDO6

Gyazo

gyazo.com

User-related data~23.6Mrecords

LEAK CONFIRMEDOAuth / integration token / Session ID / tokenUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 16, 2026
Detected
Sep 11, 2026
Detection to disclosure
5 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
4130001068185

What leaked

IdentityName, Nickname
ContactEmail address, Google SSO email address
CredentialsPassword hash, Login session ID, X (Twitter) integration token, Hashes of private-image passphrases
Account dataUser ID, Profile information, Last login date/time, Subscription plan and billing status
Device & networkDevice ID, Uploader IP address, User-Agent, EXIF location data
Communications & contentImage ID, title, source URL, OCR text

How many

  • User-related data ~23.6M records
  • Anonymous users ~18M records
  • Users registered with email ~5.6M records

Who is affected

  • Members
  • Anonymous users

Cause

A vulnerability in the image upload server was exploited, allowing a third party to execute arbitrary commands

Timeline

  1. Intrusion began
  2. Detected
  3. Intrusion stopped
  4. Detected
  5. Service suspended
  6. Reported to authority
  7. Service restored
  8. First disclosure
  9. Company issued an update
  10. Company issued an update
  11. Service suspended
  12. Company issued an update
  13. Second report
  14. Service restored
  15. Update published
  16. Company issued an update

Response

  • Blocked the entry point
  • Patched
  • Password reset
  • Revoked credentials
  • Forensic investigation
  • Vulnerability testing
  • Service stopped

Revoked authentication-related credentials and OAuth integrations; blocked the intrusion route and fixed the vulnerability; security review of the entire service; forensic investigation by an outside specialist firm; asked users to change their passwords

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Revoke connected apps and sign out everywhere. Your logged-in session itself was stolen
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources