23 Million User Records Exposed in Gyazo Data Breach
Japanese software company Helpfeel reports a security breach affecting Gyazo users, exposing 23.6 million user records and 490 million image metadata entries.
Overview of the Security Breach
Japanese software company Helpfeel has informed users of its Gyazo image-sharing platform about a security incident involving unauthorized access to user data. The breach, discovered by the firm, involved a hacker exploiting a vulnerability in Gyazo’s image upload server on September 11, which allowed the execution of malicious commands. The intruder was removed from the system the following day but had already accessed a database containing approximately 23.6 million user records.
Compromised Data
The compromised data includes names, physical addresses, password hashes, user and device identifiers, X platform integration tokens, profile details, usage metrics, and billing information. Payment card data remained unaffected, as confirmed by the company. In addition to user records, the attacker gained access to roughly 490 million image metadata entries. This metadata contains details that could enable threat actors to reconstruct and access URLs linked to user-uploaded images. A list of private images was also exposed, though the company has not disclosed the exact volume of affected private content.
Security Vulnerabilities Exposed
The breach highlights vulnerabilities in the platform’s security infrastructure, particularly around server-side access controls and data encryption practices. The incident underscores the risks associated with compromised authentication mechanisms and the potential for attackers to leverage exposed metadata to track or retrieve sensitive content.
Company Response and Recommendations
Helpfeel has not provided further details on the scope of the breach or the specific exploit used to gain initial access. The company has advised users to monitor their accounts for suspicious activity and to update passwords if necessary. No indication of financial fraud or identity theft has been reported at this time.
Broader Implications and Recommendations
The breach follows a broader trend of cyberattacks targeting cloud-based services and third-party platforms, emphasizing the need for robust security measures in shared infrastructure. Organizations using Gyazo or similar tools are encouraged to review their data protection policies and implement additional safeguards for user credentials and metadata storage.
