Gyazo Breach Exposes 23 Million User Accounts and Private Image Links

A major security flaw at the image-sharing platform Gyazo has left 23.62 million user records and hundreds of millions of image links vulnerable to unauthorized access.
Helpfeel, the Kyoto-based company behind the popular image-sharing service Gyazo, confirmed a significant data breach that exposed user details and private image links. The incident, disclosed on Wednesday, affects approximately 23.62 million user records, including email addresses, password hashes, and device identifiers. While the company stated that no credit card or payment information was compromised, the scale of the exposure requires immediate action from users to protect their accounts and personal data.
The breach also impacts about 490 million image metadata records, primarily for photos uploaded before January 2019. These records include the unique IDs that form the public links to images, which effectively act as the sole security barrier for private captures. The attacker gained access through a vulnerability in the image upload server, allowing them to execute commands on the system and access the underlying database. According to The Hacker News, this kind of server-side flaw can grant broad control over data storage, making the resulting leakage particularly difficult to contain once discovered.
Attackers Gained System-Level Access
The intrusion was not a simple data theft but a deeper compromise of the service's infrastructure. By exploiting a flaw in the upload server, the attacker was able to run arbitrary commands on Helpfeel's systems. This level of access allowed them to query the database directly, pulling out user profiles, session tokens, and integration keys for other services like Twitter and Google. The company has not specified the exact nature of the vulnerability, but it has stated that it has taken measures to invalidate compromised authentication data and restrict further access.
The exposure of session IDs and single sign-on tokens presents a specific risk of account takeover. If these tokens remain valid, an attacker could potentially log in as a user without knowing their password. Helpfeel has urged all users to change their passwords immediately and to do so on any other platforms where they used the same credentials. Users should also remain vigilant for phishing attempts, as attackers often exploit recent breaches to send convincing fraudulent emails.
Private Images Face Public Exposure
The most concerning aspect for many users is the exposure of image links. Gyazo relies on long, random IDs to keep images private until the link is shared. With 490 million of these IDs now in the hands of the attacker, the 'unguessable' nature of these links is compromised. The attacker also obtained a list identifying which images were set to private, meaning they can target specific content. Helpfeel has temporarily disabled viewing for some images to mitigate this risk, but it has not clarified which specific files are affected or how users can verify the status of their own captures.
The affected metadata also includes sensitive technical details such as IP addresses, EXIF location data, and text extracted from images via OCR. This combination allows an attacker to reconstruct a user's online behavior and physical locations over time. While Helpfeel stated that its investigation has not found evidence of image data loss, the company admitted it cannot rule out the possibility that the attacker has already viewed some private images. This uncertainty leaves users in a difficult position, as they have no way to know if their personal photos have already been seen by unauthorized parties.
Users Must Act Immediately
Given the breadth of the data exposed, Helpfeel has issued a clear directive for all Gyazo users. Changing your password is the first and most critical step, but it is not sufficient on its own. If you used the same password elsewhere, those accounts are now at risk. Additionally, users should review their account integrations, particularly if they linked their Gyazo account to social media or other services. The company is still determining exactly how many unique individuals are affected, as the 23.62 million figure includes anonymous accounts without registered emails. Until the company provides more clarity, users should assume their data is compromised and take defensive measures to secure their digital identity.






