Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.

Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech

“Thankfully, none of the information exposed in this breach should pose a direct threat to breach victims’ finances or identities. The passwords were hashed and thus cannot feasibly be reverted to plain text. HelpFeel is asking users to reset their passwords anyway, just in case. Email addresses and other identifying info could be used to craft convincing phishing messages for which victims should be on alert. Scammers might pose as Gyazo or a related company to trick victims into clicking on malicious links that lead to malware and scams.

If you shared proprietary or sensitive images on Gyazo, then those could be at risk. The IDs in the breached data linked to individual photos and allowed anyone to bypass Gyazo’s viewing permissions.”

This is a pretty bad breach. But strangely, it is not the worst one. And it will likely get worse than that. That’s a sad commentary on the state of play.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading