Gyazo Breach Exposes 23 Million User Records and Half a Billion Image Metadata Entries
Japanese software firm Helpfeel has started notifying users of its Gyazo screenshot-sharing platform that their data was compromised in a cyberattack.
Gyazo is a popular cross-platform tool used to capture screenshots, GIFs, and short screen recordings and share them via a generated link. It has a large user base, which makes this breach rather significant.
According to Helpfeel, an attacker exploited a vulnerability in the image upload server on 11 September, gaining the ability to run arbitrary commands. The intruder was removed the following day, but that was enough time to access a database containing approximately 23.6 million user records.
The exposed data includes names, email addresses, hashed passwords, user and device identifiers, X (formerly Twitter) integration tokens, profile details, usage statistics, and billing information. Payment card data was not among the stolen records, Helpfeel confirmed.
The company was careful to point out that the 23.62 million figure includes anonymous accounts with no associated email address or personal details, so the actual number of identifiable individuals affected is still being determined.
Beyond the user records, the attacker also got their hands on around 490 million image metadata entries. That metadata could potentially allow someone to reconstruct URLs for user-uploaded images, including ones intended to be private. A list of private images was also accessed, though Helpfeel has not disclosed how many.
Half a billion metadata records is a lot. Even if the user data itself is partially anonymised, the image URL reconstruction angle is a genuinely nasty wrinkle that Gyazo's privacy-conscious users will not appreciate.