Gyazo Data Breach Exposes 23.62 Million User Records
The breach turns Gyazo's private-image passphrases and EXIF location data into exposed fields, so the risk is not account takeover alone but images users believed were private.
Reporting from 1 source: ASCII.jp.
Helpfeel said on September 16 that unauthorized access to its image sharing service Gyazo exposed around 23.62 million user records and roughly 490 million metadata records for uploaded images, according to ASCII.jp. Leaked user data includes names, email addresses, password hash values, device IDs, and linked X and Google tokens. Metadata includes upload IP addresses, OCR text, and EXIF location data. Some image viewing remains disabled.
Helpfeel moved to invalidate and restrict leaked authentication data after close examination, and it has temporarily disabled viewing of some images to head off secondary harm. The company says the types and scope of affected user information differ by user and remain under investigation. It plans to email users who may have been affected.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.