A breach at Gyazo, the image-hosting service run by Kyoto-based Helpfeel, exposed roughly 23.62 million user records and about 490 million image metadata records, the company said in a notice published Wednesday. The Gyazo data breach compromised email addresses and password hashes tied to user accounts, along with metadata for images uploaded mostly in January 2019 or earlier, including the IDs that make up Gyazo’s shareable image links.
How the Gyazo data breach happened
Helpfeel said the attacker exploited a vulnerability in Gyazo’s image upload server to gain unauthorised access, according to SecurityWeek. The company has not said which flaw was involved, how it was found, or how long the server sat exposed before the intrusion was detected.
Image upload endpoints are a common weak point precisely because they need to accept high volumes of unauthenticated or lightly authenticated traffic quickly, trading scrutiny for throughput. A flaw there does not require breaking a user’s password; it can hand an attacker a path straight into the backend where accounts and files are indexed, which fits a breach that reached both the user table and the image metadata store in one incident.
What the breach exposed
The 23.62 million user records carry email addresses and password hashes, the pairing that matters most if a password was reused: an email and hash combination is enough to attempt credential-stuffing against other services once the hash is cracked or turns up in plain form elsewhere.
Helpfeel’s notice does not say which algorithm protected those passwords, and that detail matters more than the headline count. A modern, deliberately slow hash such as bcrypt or Argon2 makes cracking millions of records at once impractical; an older or fast hash such as unsalted MD5 or SHA-1 can be cracked for a large share of affected accounts in days on ordinary hardware. Until Helpfeel says which applies, the safer assumption is the weaker one.
The larger figure, 490 million image metadata records, mostly covers uploads from January 2019 or earlier. By our arithmetic, that works out to roughly 21 image records for every affected user account, more sustained use than the quick, one-off screenshot habit most people associate with the service. That metadata includes the IDs baked into Gyazo’s shareable links, the identifiers that let anyone holding the link view the image directly with no login required. Exposing those IDs does not hand over the images themselves, but it does confirm which links were ever issued, account by account, going back years.
What’s different from the Revolut breach
teqpost covered a comparable disclosure five days earlier, when Revolut disclosed a data breach exposing passports and financial records on 14 September. The two incidents put different things at risk. Revolut’s breach touched identity documents and financial data attached to accounts customers use today. Gyazo’s breach is largely a login-credential and link-metadata leak, and most of the metadata is for uploads from 2019 or earlier, images many affected users likely forgot were still online at all.
The password hashes are the part that outlasts the rest. Unlike an old image link, a reused password does not expire on its own: anyone who created a Gyazo account before 2019 and reused its password elsewhere should treat that password as compromised and change it wherever else it appears.








