Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Attackers exploited a Gyazo upload-server vulnerability, exposing 24 million user records and 490 million metadata records including IPs, EXIF locations and OCR text.
Japanese image-sharing service Gyazo, operated by developer Helpfeel, disclosed on September 11 a breach in which attackers exploited a vulnerability in an upload server, exposing nearly 24 million customer records. An additional 490 million image metadata records were exposed, including image IDs, source IPs, user agents, EXIF location data, OCR-extracted text, titles, source URLs and hashed passphrases. Because the metadata allows reconstructing image URLs, Helpfeel disabled viewing of some images and urged password resets, warning of follow-on phishing risk. Experts noted developers' screenshots often contain credentials and terminal output, though exposed data mostly predates January 2019, mitigating some impact.