logo

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

ID: fcb21d1e-8d45-5d82-978d-468d2343ec96

STIX ID: report--fcb21d1e-8d45-5d82-978d-468d2343ec96

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-09-17

Date Updated: 2026-09-18

...
...

Helpfeel (Gyazo) disclosed a security breach after an attacker exploited a vulnerability in Gyazo's image upload server to execute arbitrary commands and access the database, exposing ~23.62 million user records (emails, password hashes, session/device IDs, SSO tokens, profile/billing metadata) and ~490 million image metadata records (image IDs, upload IPs, user-agents, EXIF location data, OCR text, hashed image passphrases). The company blocked the intrusion, patched the vulnerability, disabled viewing of some images, engaged an external forensics firm, reported to Japan's regulator, and is notifying affected users; recommended user actions include changing passwords, enabling MFA, and treating shared Gyazo links as potentially exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.