conv.

All stories
SecurityFading · day 6

Helpfeel's Gyazo breach exposes 23.6M user records, 490M image metadata

Japanese software company confirms attackers exploited image server vulnerability on Sept. 11; password hashes and private image IDs compromised.

What to know

  • Attackers exploited a vulnerability in Gyazo's image upload server on September 11 to access 23.62 million user records and 490 million image metadata records; the breach was detected and patched within hours but damages were done.
  • Exposed data includes password hashes, email addresses, authentication tokens, but also sensitive metadata: EXIF location coordinates, OCR-extracted text from screenshots, and image URL IDs that could allow viewing private images and reconstructing user behavior.
  • Security researchers warn the metadata exposure is more dangerous than the credential compromise—developers commonly use Gyazo to share terminal output and config files containing API keys and secrets, now available to attackers as indexed, searchable text.
  • Helpfeel disclosed the breach on September 16 after detecting it September 11 and confirming it September 14, during which time users were told images weren't loading due to 'emergency maintenance.'

The dispute Whether password resets adequately address the breach's full scope—researchers argue it does nothing for already-viewed images or image IDs attackers can use to access private captures. · positions read across 6 posts and comments

most voices

The metadata layer poses greater risk than the credential compromise and enables attackers to reconstruct location, behavior, and access sensitive developer artifacts.

  • “The exposure most people will focus on is the 23 million user accounts, but the metadata layer is where the real reach is.”

    Security researcher · IT Nerd blog ↗
some voices

Helpfeel's disclosure of a confirmed breach as 'emergency maintenance' for five days while 23 million users remained unaware deserves scrutiny.

  • “Calling a confirmed data breach maintenance for five days while 23 million affected accounts sit unaware is a decision that deserves more scrutiny than it will probably get.”

    Security researcher · IT Nerd blog ↗

Helpfeel Gyazo operatorUnknown attacker Threat actor

Helpfeel's Gyazo breach exposes 23.6M user records, 490M image metadata
SecurityWeek

How it unfolded 1 development · click the chart to see its coverage articlesposts

Peak 2 pieces in two hours at Sep 18, 6 AM; 9 pieces over 6 days (1 article · 8 posts) Sep 18, 6 AM — 2 pieces · 1 article · 1 post — Mastodon 1, Newswires 1Sep 18, 8 AM — quietSep 18, 10 AM — 1 piece · 1 post — Mastodon 1Sep 18, 12 PM — quietSep 18, 2 PM — quietSep 18, 4 PM — 1 piece · 1 post — Mastodon 1Sep 18, 6 PM — quietSep 18, 8 PM — quietSep 18, 10 PM — quietSep 19, 12 AM — quietSep 19, 2 AM — quietSep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — quietSep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — quietSep 20, 10 AM — quietSep 20, 12 PM — 1 piece · 1 post — Mastodon 1Sep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — 1 piece · 1 post — Mastodon 1Sep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — 1 piece · 1 post — Mastodon 1Sep 21, 12 PM — quietSep 21, 2 PM — quietSep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — 1 piece · 1 post — Mastodon 1Sep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — 1 piece · 1 post — Mastodon 1Today, 12 AM — quietToday, 2 AM — quietToday, 4 AM — quietToday, 6 AM — quietToday, 8 AM — quietToday, 10 AM — quiet 1
Sep 19Sep 20Sep 21Sep 22yesterdaynow · 11:54 AM ET
  1. 1

    Security researchers highlight metadata exposure as greater threat than credential breach

    Expert analysis warns that the 490 million image metadata records—containing EXIF location data, OCR-extracted text, session IDs, and image URL data—pose greater risk than the 23 million user account credentials. Metadata could allow reconstructing user behavior, location history, and accessing developer screenshots containing API keys and credentials.

    “The 490 million metadata records are the more serious number. Gyazo is a screenshot tool. Developers use it constantly to share what is on their screen, which means those images contain terminal output, API keys, credentials in config files.”
    — Security researcher (analysis)
    1. first by SecurityWeek, 6d ago

    • beyondmachines1@infosec.exchange

      Helpfeel Confirms Gyazo Breach Exposing 23 Million User Records Helpfeel's Gyazo service suffered a data breach after attackers exploited an image upload server vulnerability to execute arbitrary commands and access databases. The incident exposed 23.62 million user records and 490 million image metadata records, including password hashes and…

      beyondmachines1@infosec.exchangeMastodon6d agoview on Mastodon ↗
    2 more of the top 3 · 6 posts in this stretch
    • The_IT_Nerd@noc.social

      Gyazo breach exposes 23.62M user records and metadata for 490M images Helpfeel has confirmed a major data breach affecting its Gyazo image-sharing service, exposing approximately 23.62 million user records and roughly 490 million records containing metadata associated with uploaded images.... https:// itnerd.blog/2026/09/18/gyazo-b…

      The_IT_Nerd@noc.socialMastodon5d agoview on Mastodon ↗
    • DevaOnBreaches@infosec.exchange

      Gyazo has confirmed a major # databreach after hackers exploited a server vulnerability, stealing about 23.6M user records. Exposed data may include emails, password hashes, IDs, session data and subscription details, plus metadata from 490M images. https://www. bleepingcomputer.com/news/secu…

      DevaOnBreaches@infosec.exchangeMastodon3d agoview on Mastodon ↗
    all of them →
  2. background

    Helpfeel publicly discloses breach affecting 23.62 million user records — The company revealed the breach exposed approximately 23.62 million user records including names, email addresses, password hashes, X integration tokens, and billing information, plus roughly 490 million image metadata records containing EXIF coordinates, OCR-extracted text, and image URL construction data.

  3. background

    Helpfeel confirms breach; temporarily suspends image delivery — Helpfeel confirmed the data breach and temporarily suspended image delivery to prevent unauthorized viewing via exposed image IDs. The company hired external forensic specialists to investigate the full scope of the compromise.

  4. background

    Helpfeel detects breach and removes attacker; patches vulnerability — Helpfeel detected the unauthorized access on the evening of September 11 and stopped the attacker by early hours of September 12. The company fixed the vulnerability the same day.

  5. background

    Attacker exploits image upload server vulnerability on Gyazo — A hacker exploited a vulnerability in Gyazo's image upload server to execute malicious commands and gain unauthorized access to the company's database containing user records and image metadata.

What people are saying 3 voices from 1 site · best of 6 · verbatim

Still unanswered
  • What was stored in the 490 million image metadata records and how much of it contained sensitive developer information?
  • How many of the private images with exposed IDs were actually accessed by the attacker?