Breaking
Cyber CrimeDeveloping Story

Gyazo Breach Exposes 23.6 Million Records

Helpfeel reports a September 11 cyberattack that compromised 23.62 million user records and 490 million image metadata records tied to its Gyazo service.

··2 hours ago·4 min read
brown padlock on black computer keyboard
Photo by FlyD on Unsplash

On September 11, an unidentified attacker slipped past Gyazo's defenses, exploiting a vulnerability to upload malware, seize control of the service's servers, and run arbitrary commands. The intrusion went unnoticed until a subsequent investigation revealed the scope: 23.62 million user records and 490 million image metadata records had been compromised.

The company behind Gyazo, Japanese customer-support and knowledge-base firm Helpfeel, disclosed the breach in a notification published earlier this week. Helpfeel, which employs more than 200 people and operates a modern help center, intelligent search, and AI support agent, is now grappling with the fallout as it continues to investigate how the attacker gained access.

How the attackers got in

According to Helpfeel's breach notification, the attacker abused a vulnerability to upload malware onto the servers, gaining a foothold that allowed them to execute arbitrary commands. The exact nature of the vulnerability has not been disclosed, but the method — upload malware, gain access, run commands — suggests a common attack chain that can lead to full server compromise.

Once inside, the attacker moved to exfiltrate data. The breach was confirmed after an internal investigation, which found that 23.62 million records had been compromised. However, Helpfeel cautions that the actual number of affected individuals is likely lower, because multiple records can belong to the same user and many records were generated by customers without user accounts.

What data was taken

The stolen records include a wide range of personally identifiable information (PII) and account details. Helpfeel confirmed that names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with Google SSO, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics were all compromised.

Notably, the breach also exposed Google SSO tokens and X (formerly Twitter) integration tokens, which could potentially be used to access linked accounts if not revoked. Password hashes were also taken, though Helpfeel has not specified the hashing algorithm used.

In a statement, Helpfeel said: “We have confirmed that no payment information, including credit card numbers, was disclosed without authorization.”

Image metadata and private images

Beyond user records, the attackers accessed a massive trove of image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised. This metadata includes image IDs, the source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.

Because some of this metadata is used to generate image URLs, Helpfeel does not rule out the possibility that the attackers viewed actual images. The company stated: “We have temporarily disabled viewing of some images to prevent further harm. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”

Responding to the breach

Helpfeel has disabled viewing of some images as a precaution and is continuing its investigation. The company has not disclosed whether it has notified law enforcement or if it has a timeline for restoring full functionality. Affected users are advised to change their passwords, especially if they reused the same password on other sites, and to revoke any linked Google or X accounts that may have been compromised.

The breach notification did not specify whether Helpfeel has implemented additional security measures beyond disabling image viewing, such as patching the exploited vulnerability or enhancing monitoring. The company has also not provided a timeline for when the investigation will conclude.

The scope of the breach in numbers

  • 23.62 million user records compromised
  • 490 million image metadata records compromised
  • September 11 date of the breach
  • 200+ employees at Helpfeel

Risks for affected users

For users of Gyazo, the exposure of personal data and image metadata poses several risks. The stolen PII can be used for phishing, identity theft, or account takeover attempts. The inclusion of Google SSO tokens and X integration tokens is particularly concerning, as these could allow attackers to access linked accounts if the tokens were not revoked.

Image metadata, including EXIF location data, could reveal sensitive information about where photos were taken, potentially exposing home addresses or other private locations. OCR text extracted from images might contain additional personal or confidential information. The hashed passphrases for private images, if cracked, could allow unauthorized access to private content.

What Helpfeel has said

Helpfeel has been transparent about the breach, confirming the number of records and the types of data involved. In its notification, the company emphasized that no payment information was disclosed without authorization. It also acknowledged the possibility that private images may have been viewed and stated that it has temporarily disabled viewing of some images to prevent further harm.

The company has not yet responded to requests for additional comment on the nature of the vulnerability or the steps it is taking to prevent future breaches.

Why this matters

This breach highlights the growing threat of cyberattacks targeting cloud-based services that store large amounts of user data. For Helpfeel, the incident could undermine user trust and lead to regulatory scrutiny, especially given the exposure of PII and image metadata. For users, the breach serves as a reminder to practice good security hygiene: use unique passwords, enable two-factor authentication where possible, and be cautious about the metadata embedded in images they upload to online services.

As the investigation continues, affected users should monitor their accounts for suspicious activity and consider revoking any linked third-party access tokens. The full impact of the breach may not be known for some time, but the scale of the data loss underscores the importance of robust security measures for services handling sensitive user information.

#gyazo#helpfeel#data breach#pii#image metadata#cyberattack

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories