Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Read original article ↗AI Summary
A breach at Gyazo, an image-sharing service operated by Helpfeel, exposed approximately 23.62 million user records and 490 million image metadata records. The attacker exploited a vulnerability in Gyazo's image upload server to gain unauthorized access, execute arbitrary commands, and extract sensitive data including email addresses, password hashes, session IDs, and image metadata such as image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, and hashed passphrases for private images. Helpfeel confirmed the breach on September 14, 2026, reported it to Japanese authorities, and took steps to block the attacker and fix the vulnerability, though it did not disclose the specific nature of the flaw. The company temporarily disabled access to some images to prevent further unauthorized viewing and urged all users to change their passwords due to the risk of credential reuse.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.