Gyazo Data Breach Exposes 23 Million User Records
Attackers exploited a flaw in Gyazo's image upload server, exposing 23.6 million user records and about 490 million image metadata entries.
Japanese software company Helpfeel is notifying Gyazo users that attackers exploited a vulnerability in the image upload server on September 11, ran malicious commands, and accessed a database with approximately 23.62 million user records before being locked out the next day. Stolen data includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile details and billing information. About 490 million image metadata records were also exposed, including upload IP addresses, User-Agent data, EXIF location information, OCR text and hashed passphrases for private images, plus a list of private images. Payment card data was not affected, remediation is complete, and the investigation is ongoing.