Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed a massive amount of user data, including 23.62 million records with email addresses and password hashes, and 490 million image metadata records. The attacker gained access through a vulnerability in Gyazo's image upload server, ran arbitrary commands, and accessed the database. Helpfeel has taken steps to mitigate the damage, including disabling image viewing and notifying affected users, but the potential for further exposure remains due to the leaked image IDs and the possibility that third parties may have viewed private images.
A security breach at Gyazo, Helpfeel's image-sharing service, exposed a massive amount of user data. The incident resulted in the exposure of approximately 23.62 million user records, including email addresses and password hashes, alongside 490 million image metadata records, primarily for images registered in January 2019 or earlier. The attacker gained access through a vulnerability in Gyazo’s image upload server, enabling them to run arbitrary commands on Helpfeel’s systems and subsequently access Gyazo’s database.
Helpfeel said it noticed suspicious activity on the evening of September 11, Japan time, and by the early hours of September 12, it had blocked the attacker’s access routes and fixed the vulnerability. However, the company acknowledged that the leaked image IDs could be used to view images without permission, and that the attacker also obtained a list identifying private images, potentially leading to further exposure.
Affected user records include: Name, Email address, Password hash, User ID, Device ID, Login session ID, X (formerly Twitter) integration token, Email address used for Google single sign-on (SSO), Profile information, Language preference, Registration date and time, Last login date and time, Subscription plan, Billing status, Usage statistics. The metadata records include Image ID, IP address used for the upload, User-Agent, EXIF location data, OCR text extracted from the image, Image title, Source URL and other metadata, and hashed passphrase for private images.
Helpfeel temporarily disabled image viewing to prevent further harm and is currently investigating the extent of the exposure. It has reported the incident to Japan’s Personal Information Protection Commission and will email users it identifies as affected. Gyazo’s help pages describe a private capture as one set to "Only me," which cannot be viewed even by someone who knows the link, and one locked with a password, both available only on paid plans. The OCR text field comes from a Gyazo feature that reads the text in a user’s captures, allowing them to search it, and is only visible to the user who enabled it.
Helpfeel’s other products, Helpfeel and Cosense, run on separate systems and have not been affected, although images shown inside them may not load while image delivery is suspended. Outside specialists are now running a forensic investigation, and Helpfeel is taking questions through Gyazo’s support form.
