Helpfeel has confirmed a major data breach affecting its Gyazo image-sharing service, exposing approximately 23.62 million user records and roughly 490 million records containing metadata associated with uploaded images.
An attacker exploited a vulnerability in Gyazo’s image upload server to execute arbitrary commands and access the company’s database.
Exposed user information may include names, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses and profile information, as well as image IDs used to construct Gyazo URLs, IP addresses, EXIF location data, OCR-extracted text and other image metadata.
Helpfeel said the exposed IDs could potentially be used to access corresponding images without authorization and that it cannot rule out the possibility that some private images were viewed. The company has temporarily disabled access to some images and is asking all Gyazo users to change their passwords.
Seemant Sehgal, Founder & CEO, BreachLock:
“An image upload server that accepts arbitrary command execution is a fundamental misconfiguration, and the fact that it sat adjacent to a database holding half a billion metadata records tells you the internal segmentation was not there. The exposure most people will focus on is the 23 million user accounts, but the metadata layer is where the real reach is. EXIF coordinates, OCR-extracted text, session IDs, and image URL construction data give an attacker enough to reconstruct user behavior and location history for tens of millions of people who uploaded a screenshot and never thought about it again.”
Michael Bell, Founder & CEO, Suzu Labs:
“Most people will see 23 million email addresses and password hashes and treat this like a standard credential breach. It is not. The 490 million metadata records are the more serious number.
“Gyazo is a screenshot tool. Developers use it constantly to share what is on their screen, which means those images contain terminal output, API keys, credentials in config files, internal application screenshots, and sensitive documents. The OCR feature that makes captures searchable also extracted and stored all of that text. Whatever text was visible in those screenshots is now in an attacker’s hands as searchable, indexed data, not just pixels.
“The EXIF location data compounds this. Users who uploaded photos from mobile devices had GPS coordinates embedded in those images. Home addresses, workplace locations, the places people visit regularly. Password resets will not change any of that.
“The security model for private captures on free accounts was a 32-character image ID that was “hard to guess.” That was the only thing protecting those images. Now the IDs are exposed, and Helpfeel has acknowledged it cannot rule out that private images were viewed. Telling users to change their passwords fixes the credential piece. It does nothing for images an attacker already has or for image IDs they can now use to retrieve captures they have not looked at yet.
“There is also a disclosure question worth asking. The breach was detected September 11, confirmed on September 14, and made public on September 16. During that window Gyazo told users the images not loading were due to “emergency maintenance.” Calling a confirmed data breach maintenance for five days while 23 million affected accounts sit unaware is a decision that deserves more scrutiny than it will probably get.”
Seriously, everybody needs to figure out what their risk exposure is to getting pwned and get ahead of it by reducing or eliminating their exposure. Otherwise you get this. Every. Single. Time.
Related
This entry was posted on September 18, 2026 at 5:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Gyazo breach exposes 23.62M user records and metadata for 490M images
Helpfeel has confirmed a major data breach affecting its Gyazo image-sharing service, exposing approximately 23.62 million user records and roughly 490 million records containing metadata associated with uploaded images.
An attacker exploited a vulnerability in Gyazo’s image upload server to execute arbitrary commands and access the company’s database.
Exposed user information may include names, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses and profile information, as well as image IDs used to construct Gyazo URLs, IP addresses, EXIF location data, OCR-extracted text and other image metadata.
Helpfeel said the exposed IDs could potentially be used to access corresponding images without authorization and that it cannot rule out the possibility that some private images were viewed. The company has temporarily disabled access to some images and is asking all Gyazo users to change their passwords.
Seemant Sehgal, Founder & CEO, BreachLock:
“An image upload server that accepts arbitrary command execution is a fundamental misconfiguration, and the fact that it sat adjacent to a database holding half a billion metadata records tells you the internal segmentation was not there. The exposure most people will focus on is the 23 million user accounts, but the metadata layer is where the real reach is. EXIF coordinates, OCR-extracted text, session IDs, and image URL construction data give an attacker enough to reconstruct user behavior and location history for tens of millions of people who uploaded a screenshot and never thought about it again.”
Michael Bell, Founder & CEO, Suzu Labs:
“Most people will see 23 million email addresses and password hashes and treat this like a standard credential breach. It is not. The 490 million metadata records are the more serious number.
“Gyazo is a screenshot tool. Developers use it constantly to share what is on their screen, which means those images contain terminal output, API keys, credentials in config files, internal application screenshots, and sensitive documents. The OCR feature that makes captures searchable also extracted and stored all of that text. Whatever text was visible in those screenshots is now in an attacker’s hands as searchable, indexed data, not just pixels.
“The EXIF location data compounds this. Users who uploaded photos from mobile devices had GPS coordinates embedded in those images. Home addresses, workplace locations, the places people visit regularly. Password resets will not change any of that.
“The security model for private captures on free accounts was a 32-character image ID that was “hard to guess.” That was the only thing protecting those images. Now the IDs are exposed, and Helpfeel has acknowledged it cannot rule out that private images were viewed. Telling users to change their passwords fixes the credential piece. It does nothing for images an attacker already has or for image IDs they can now use to retrieve captures they have not looked at yet.
“There is also a disclosure question worth asking. The breach was detected September 11, confirmed on September 14, and made public on September 16. During that window Gyazo told users the images not loading were due to “emergency maintenance.” Calling a confirmed data breach maintenance for five days while 23 million affected accounts sit unaware is a decision that deserves more scrutiny than it will probably get.”
Seriously, everybody needs to figure out what their risk exposure is to getting pwned and get ahead of it by reducing or eliminating their exposure. Otherwise you get this. Every. Single. Time.
Share this:
Like this:
Related
This entry was posted on September 18, 2026 at 5:11 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.