A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“Thankfully, none of the information exposed in this breach should pose a direct threat to breach victims’ finances or identities. The passwords were hashed and thus cannot feasibly be reverted to plain text. HelpFeel is asking users to reset their passwords anyway, just in case. Email addresses and other identifying info could be used to craft convincing phishing messages for which victims should be on alert. Scammers might pose as Gyazo or a related company to trick victims into clicking on malicious links that lead to malware and scams.
If you shared proprietary or sensitive images on Gyazo, then those could be at risk. The IDs in the breached data linked to individual photos and allowed anyone to bypass Gyazo’s viewing permissions.”
This is a pretty bad breach. But strangely, it is not the worst one. And it will likely get worse than that. That’s a sad commentary on the state of play.
Related
This entry was posted on September 17, 2026 at 4:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“Thankfully, none of the information exposed in this breach should pose a direct threat to breach victims’ finances or identities. The passwords were hashed and thus cannot feasibly be reverted to plain text. HelpFeel is asking users to reset their passwords anyway, just in case. Email addresses and other identifying info could be used to craft convincing phishing messages for which victims should be on alert. Scammers might pose as Gyazo or a related company to trick victims into clicking on malicious links that lead to malware and scams.
If you shared proprietary or sensitive images on Gyazo, then those could be at risk. The IDs in the breached data linked to individual photos and allowed anyone to bypass Gyazo’s viewing permissions.”
This is a pretty bad breach. But strangely, it is not the worst one. And it will likely get worse than that. That’s a sad commentary on the state of play.
Share this:
Like this:
Related
This entry was posted on September 17, 2026 at 4:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.