Gyazo, the image-sharing service run by Helpfeel, just disclosed a serious security breach. The numbers are big. About 23.62 million user records were exposed. That includes email addresses and password hashes. On top of that, roughly 490 million image metadata records were also accessed.
The company published a notice on Wednesday. They’re based in Kyoto. And they’re asking every Gyazo user to change their password immediately.
Here’s what happened and what you need to do.
Quick Summary
|
What |
Details |
|
Service |
Gyazo (Helpfeel) |
|
User records exposed |
~23.62 million |
|
Image metadata exposed |
~490 million |
|
Data included |
Emails, password hashes, image IDs, tokens |
|
Cause |
Vulnerability in image upload server |
|
Action required |
Change passwords, check private images |
What Was Exposed?
Helpfeel listed the fields that may have been exposed. Not every record has every field. But here’s the full list:
- Name (whatever the user entered, like a nickname)
- Email address
- Password hash
- User ID
- Device ID
- Login session ID
- X (formerly Twitter) integration token, if connected
- Google SSO email address, if connected
- Profile information
- Language preference
- Registration date and time
- Last login date and time
- Subscription plan
- Billing status (no credit card numbers or payment details)
- Usage statistics
The 23.62 million figure counts records, not people. Helpfeel says it includes anonymous accounts with no registered email address. They’re still working out how many actual people had personal info exposed.
No payment info was leaked. That’s one piece of good news.
The Image Metadata Problem
This is the part that worries me more.
Helpfeel says about 490 million image metadata records were exposed. Most of those are for images from January 2019 or earlier. That metadata includes the image IDs that make up Gyazo links.
Why does that matter? Because on Gyazo, a capture stays private until its link is shared. Anyone with the link can see it. The ID is what makes the link unguessable. If someone has the ID, they have the link. And if they have the link, they can view the image.
Helpfeel says those IDs could be used to view images without permission. They’ve temporarily disabled viewing for some of them. But they haven’t said which ones.
For free accounts, Gyazo only shows your 10 most recent captures on the site. But older captures aren’t deleted. They’re still accessible to anyone with the URL. So if your old image ID leaked, someone could still find it.
What About Private Images?
Helpfeel also said the attacker obtained a list identifying private images. They “cannot rule out the possibility” that some private images were viewed.
On Gyazo, “private” can mean two things. One is “Only me,” which the help pages say cannot be viewed even with the link. The other is password-protected. Both are paid features. Helpfeel hasn’t said which one they mean or how those images could have been viewed.
There’s also OCR text. Gyazo has a paid feature that scans your images and extracts text so you can search it. The help pages say “Only you can see OCR results.” That OCR text was in the exposed metadata. So if you used that feature, the text from your images may have been exposed too.
How Did This Happen?
Helpfeel says the attacker got in through a vulnerability in Gyazo’s image upload server. They ran arbitrary commands on Helpfeel’s systems and accessed the Gyazo database. The company hasn’t said what kind of flaw it was.
Timeline:
|
Date |
Event |
|
Sept 11 (evening JST) |
Suspicious activity detected |
|
Sept 12 (early hours) |
Access routes blocked, connections cut, vulnerability fixed |
|
Sept 14 |
Confirmed data exposure; suspended image delivery |
|
Sept 15 |
Reported to Japan’s privacy regulator; new uploads resumed |
|
Sept 16 |
Public notice published |
While images were failing to load, Gyazo’s public notices called it “maintenance.” They didn’t mention the breach until September 16.
What Helpfeel Is Doing
Helpfeel says it has reviewed the exposed authentication data and taken “necessary measures, including invalidation and restrictions.” They didn’t say which items were invalidated.
They’ve asked every user to change their password. And to change it on any other service that uses the same or a similar password. They also want users to watch for suspicious emails or messages related to the incident.
Outside specialists are running a forensic investigation. Helpfeel says it will email users it identifies as affected. For anonymous accounts, notices will go on Gyazo’s website. Questions can go through Gyazo’s support form.
Gyazo normally emails a verification code when you log in from a new IP address. Helpfeel hasn’t said whether the exposed session IDs are still valid.
What You Should Do Right Now
1. Change your Gyazo password.
Do it now. Don’t wait.
2. Change it everywhere else you used it.
If you reused that password on other sites, change it there too. This is the most important step.
3. Watch out for suspicious emails or messages.
The attackers can use the leaked email addresses for phishing attacks.
4. Review your private images.
If you have private captures on Gyazo, think about whether you need to keep them there. You can’t tell which images were affected. So treat old private links as potentially exposed.
5. Watch for unusual account activity.
Check your login history. Look for anything you don’t recognize.
6. Consider enabling two-factor authentication.
If Gyazo supports it, turn it on. It won’t stop this kind of breach, but it helps with account takeover.
The Bottom Line
Gyazo had a major breach. 23.62 million user records and 490 million image metadata records were exposed. Email addresses, password hashes, and image IDs are in the wild. Helpfeel fixed the vulnerability and is investigating. But the damage is done.
If you use Gyazo, change your password. Change it everywhere else you used it. Be careful with old image links. And keep an eye out for phishing.
Quick Reference:
|
Key Point |
Detail |
|
User records |
~23.62 million |
|
Image metadata |
~490 million |
|
Cause |
Image upload server vulnerability |
|
Data exposed |
Emails, password hashes, image IDs, tokens |
|
Action |
Change passwords, review private images |
What to Do:
- Change Gyazo password
- Change it on other sites
- Watch for phishing
- Review private images
- Check account activity
- Enable 2FA if available
FAQ Section
What is the Gyazo security breach?
A breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records and 490 million image metadata records.
What type of data was compromised?
Email address, password hashes, names, device IDs, session IDs, social tokens, profiles, and image IDs. No payment cards were compromised.
How was the breach conducted?
Via an exploit in Gyazo’s image upload server. Commands were executed on Helpfeel’s systems and database of Gyazo was accessed.
What should I do?
Change your Gyazo password immediately. Change it on any other service where you used the same or similar password. Watch for phishing.
Are my private images exposed?
Helpfeel says it cannot rule out that some private images were viewed. It’s unclear which images are affected. Treat old private links as potentially exposed.
Was payment information leaked?
No. Helpfeel says no credit card numbers or payment details were exposed.