Data breaches

Gyazo breach: account records and image metadata exposed

Helpfeel confirms an intrusion on Gyazo's upload server and the exposure of about 23.62 million user records plus image metadata.

Conceptual illustration: Gyazo breach: account records and image metadata exposed
Conceptual illustration · SecurCheck

What is confirmed

Helpfeel dates the intrusion to 11 September: an upload-server flaw allowed command execution and unauthorised database access. The company says it closed the entry route on 12 September.

Its notice counts about 23.62 million account records, including anonymous accounts, and roughly 490 million older image metadata records; neither figure equals unique people or publicly visible images.

What it means

Exposed fields vary by account and may include email, password hash, session IDs or linked-service tokens. Metadata may include link identifiers, IP, EXIF location or OCR text.

Helpfeel says card payment data is not among the confirmed exposed information and continues investigating possible viewing of some non-public images.

What to do

Change your Gyazo password when the service allows it, then any reused passwords elsewhere; review linked apps and unexpected messages.

If you shared sensitive captures, inventory relevant links and follow official updates before concluding a particular image was viewed.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Helpfeel — avis officiel Gyazo (japonais)