Breaches · 14h ago
Gyazo said a breach of its image upload server exposed 23.62 million user records and 490 million image metadata records, mostly for captures from January 2019 or earlier. Helpfeel, which runs Gyazo, said the attacker ran arbitrary commands on its systems and reached the database.
The critical part is the image-link IDs: Gyazo builds each private capture URL from a 32-character ID, and Helpfeel said those IDs could be used to view images without permission. That means the exposure is not just account data; old shared captures can remain reachable if someone has the link or learns the ID, even after a password change.
For teams that used Gyazo links or embedded captures, the lingering exposure sits in the URLs themselves. The report also says some authentication data was invalidated, but it does not say which session or integration tokens were killed, so the full cleanup picture is still incomplete.
5 sources covering this story
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
A breach at image-sharing service Gyazo on September 11 is still playing out
Hackers exploit Gyazo server flaw to steal 23.6 million user records - Help Net Security
Helpfeel confirms a Gyazo data breach exposing 23.62 million user records and metadata from hundreds of millions of images.
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records.
23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Gyazo says a breach exposed 23.62 million user records and 490 million image metadata records, including IDs used to build image links.
Part of the PlainSec briefing for 2026-09-21