Gyazo image platform suffers massive data breach

Gyazo, a screenshot-sharing service owned by Helpfeel, confirmed a data breach exposing 23.62 million user records and 490 million image metadata records after attackers exploited a server vulnerability. The breach occurred on or before September 18 and compromised user emails, usernames, and hashed passwords.

15 reports · 13 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

stream:bsky-jetstreamother11d ago kagi ↗

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a no… #hackernews #meta #news A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user recor

Helpfeel Confirms Gyazo Breach Exposing 23 Million User Records Helpfeel's Gyazo service suffered a data breach after attackers exploited an image upload server vulnerability to execute arbitrary comm

mastodon:infosec-exchangeother11d ago kagi ↗

Helpfeel Confirms Gyazo Breach Exposing 23 Million User Records Helpfeel's Gyazo service suffered a data breach after attackers exploited an image upload server vulnerability to execute arbitrary commands and access databases. The incident exposed 23.62 million user records and 490 million image metadata records, including password hashes and private image IDs. **** # cybersecurity # infosec # inc

Reward: You've received a Coffin-Tier Bronze Breach Badge and one complimentary shrug from HR. https:// beyondmachines.net/event_detai ls/helpfeel-confirms-gyazo-breach-exposing-23-million-user-record

mastodon:infosec-exchangeother11d ago kagi ↗

Reward: You've received a Coffin-Tier Bronze Breach Badge and one complimentary shrug from HR. https:// beyondmachines.net/event_detai ls/helpfeel-confirms-gyazo-breach-exposing-23-million-user-records-q-t-a-h-h/gD2P6Ple2L # DataBreach # CyberSecurity # Gyazo # ImageUpload # VulnerabilityExploit # AchievementUnlocked (3/3)

The incident has been formally onboarded into compliance review: 23.62 million user records exposed, password hashes included, plus 490 million image metadata records — among them private image IDs. T

mastodon:infosec-exchangeother11d ago kagi ↗

The incident has been formally onboarded into compliance review: 23.62 million user records exposed, password hashes included, plus 490 million image metadata records — among them private image IDs. That is a truly impressive headcount for a single upload endpoint's funeral. Per standard reanimated-risk protocol: rotate any reused passwords immediately and enable MFA before your credentials comple

🚨 Gyazo breach: 23.62M accounts affected, with metadata tied to 490M+ images reportedly exposed. The exposed data reportedly includes: • Email addresses & usernames • Password hashes • Session IDs •

mastodon:infosec-exchangeother11d ago kagi ↗

🚨 Gyazo breach: 23.62M accounts affected, with metadata tied to 490M+ images reportedly exposed. The exposed data reportedly includes: • Email addresses & usernames • Password hashes • Session IDs • Device IDs • X integration tokens • OCR text • IP addresses & EXIF data • Gyazo image IDs The OCR + image-ID exposure is particularly concerning for screenshots containing credentials, API keys, inter

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. https://www. bleepingcompu

mastodon:infosec-exchangeother11d ago kagi ↗

The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. https://www. bleepingcomputer.com/news/secu rity/gyazo-server-flaw-exploited-to-steal-236-million-user-records/

🚨🇯🇵 Gyazo confirms breach exposing 23.62M user records and 490M image metadata records Gyazo operator Helpfeel has confirmed a major data breach after an attacker exploited a vulnerability in the i

mastodon:infosec-exchangeother11d ago kagi ↗

🚨🇯🇵 Gyazo confirms breach exposing 23.62M user records and 490M image metadata records Gyazo operator Helpfeel has confirmed a major data breach after an attacker exploited a vulnerability in the image-sharing service's upload server and gained unauthorized access to internal systems. ⠀ Approximately 23.62 million user records were exposed, potentially including: • Names and nicknames • Email a

Gyazo breach exposes 23.6M records after attackers exploited an image upload server flaw. The incident highlights how URL secrecy alone fails as a privacy model when https:// deafnews.it/en/article/gy

mastodon:infosec-exchangeother11d ago kagi ↗

Gyazo breach exposes 23.6M records after attackers exploited an image upload server flaw. The incident highlights how URL secrecy alone fails as a privacy model when https:// deafnews.it/en/article/gyazo-b reach-exposes-236-million-records-the-failure-of-security-by-obscurity

Helpfeel confirmed RCE via a Gyazo image upload vulnerability on Sept 11, with access to a database of ~23.62M user records. Account data and private image links were exposed, enabling takeover and un

mastodon:infosec-exchangeother11d ago kagi ↗

Helpfeel confirmed RCE via a Gyazo image upload vulnerability on Sept 11, with access to a database of ~23.62M user records. Account data and private image links were exposed, enabling takeover and unauthorized access to private captures. # Gyazo # DataBreach # InfoSec https:// cyberworldops.eu/en/gyazo-serv er-intrusion-puts-account-data-and-private-image-links-at

🤖 Gyazo confirmed a data breach: attackers exploited a server vulnerability to steal 23.6 million user records from the screenshot-sharing platform, reportedly including emails, usernames and hashed

mastodon:infosec-exchangeother10d ago kagi ↗

🤖 Gyazo confirmed a data breach: attackers exploited a server vulnerability to steal 23.6 million user records from the screenshot-sharing platform, reportedly including emails, usernames and hashed passwords. 🔗 https://www. bleepingcomputer.com/news/secu rity/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ # DataBreach # InfoSec # CyberSec

🏆 New Achievement! Screenshot Taken — Of Everything You Ever Did! Welcome, new player, to the Mandatory Data Exposure Tutorial. This is a required quest; you cannot skip it. Gyazo, the image-hosting

mastodon:infosec-exchangeother10d ago kagi ↗

🏆 New Achievement! Screenshot Taken — Of Everything You Ever Did! Welcome, new player, to the Mandatory Data Exposure Tutorial. This is a required quest; you cannot skip it. Gyazo, the image-hosting and screenshot service, has unlocked a breach affecting 23.62 million user records and a staggering 490 million image metadata records. Please pay attention, as this mechanic will persist throughout t