← BACK TO FEED
data breachGyazocybersecurityprivacyimage sharing

Gyazo Breach Exposes 23 Million User Records and Half a Billion Image Metadata Entries

Helpfeel, the Japanese company behind the Gyazo image-sharing service, has disclosed a data breach affecting approximately 23.6 million user records after a hacker exploited a vulnerability in its image upload server on September 11. Compromised data includes names, email addresses, password hashes, billing information, and other account details, though payment card information was not affected. Additionally, around 490 million image metadata records were accessed, potentially allowing attackers to reconstruct URLs and access user-uploaded images.

Japanese software firm Helpfeel has started notifying users of its Gyazo screenshot-sharing platform that their data was compromised in a cyberattack.

Gyazo is a popular cross-platform tool used to capture screenshots, GIFs, and short screen recordings and share them via a generated link. It has a large user base, which makes this breach rather significant.

According to Helpfeel, an attacker exploited a vulnerability in the image upload server on 11 September, gaining the ability to run arbitrary commands. The intruder was removed the following day, but that was enough time to access a database containing approximately 23.6 million user records.

The exposed data includes names, email addresses, hashed passwords, user and device identifiers, X (formerly Twitter) integration tokens, profile details, usage statistics, and billing information. Payment card data was not among the stolen records, Helpfeel confirmed.

The company was careful to point out that the 23.62 million figure includes anonymous accounts with no associated email address or personal details, so the actual number of identifiable individuals affected is still being determined.

Beyond the user records, the attacker also got their hands on around 490 million image metadata entries. That metadata could potentially allow someone to reconstruct URLs for user-uploaded images, including ones intended to be private. A list of private images was also accessed, though Helpfeel has not disclosed how many.

Half a billion metadata records is a lot. Even if the user data itself is partially anonymised, the image URL reconstruction angle is a genuinely nasty wrinkle that Gyazo's privacy-conscious users will not appreciate.

READ NEXT
Spain's Data Watchdog Gets First AI Agent Data Breach Report. Should We Panic?Surfshark Misconfigured Server Breach: User Data Unaffected, But It's Still EmbarrassingRansomware Surges While Everyone's Busy Watching the AI Show