Gyazo said a breach of its image upload server exposed 23.62 million user records and 490 million image metadata records, mostly for captures from January 2019 or earlier. Helpfeel, which runs Gyazo, said the attacker ran arbitrary commands on its systems and reached the database.
The critical part is the image-link IDs: Gyazo builds each private capture URL from a 32-character ID, and Helpfeel said those IDs could be used to view images without permission. That means the exposure is not just account data; old shared captures can remain reachable if someone has the link or learns the ID, even after a password change.
For teams that used Gyazo links or embedded captures, the lingering exposure sits in the URLs themselves. The report also says some authentication data was invalidated, but it does not say which session or integration tokens were killed, so the full cleanup picture is still incomplete.
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.