Morning Edition ·
Technology · Data Breach KYOTO, JAPAN

Screenshot Tool Gyazo Discloses Breach Exposing 23.6 Million Users' Data

Attackers broke into the image-hosting service through its upload server and pulled password hashes, session tokens and nearly half a billion image records, the Japanese owner says.

Screenshot Tool Gyazo Discloses Breach Exposing 23.6 Million Users' Data
Illustrative image of code on a computer screen, not the actual Gyazo intrusion. — Photograph: Bernd Dittrich / Unsplash
SHARE X f in

Gyazo, the widely used screenshot and image-hosting service, disclosed that attackers breached its systems earlier this month and made off with personal data on roughly 23.62 million users, along with metadata tied to some 490 million uploaded images, according to its owner, the Kyoto-based company Helpfeel.

The company said the intrusion began through a vulnerability in Gyazo's image upload server, which the attacker used to run arbitrary commands on Helpfeel's broader systems before reaching the underlying database, according to a report from The Hacker News. Helpfeel has not disclosed the specific type of flaw that allowed the initial access.

The user records exposed include email addresses, password hashes, device and session IDs, Twitter integration tokens, Google single sign-on email addresses, subscription and billing status, and account registration and login dates. Separately, roughly 490 million records tied to images uploaded in or before January 2019 were also compromised, encompassing image IDs, the IP addresses used to upload them, browser user-agent strings, embedded EXIF location data, OCR-extracted text pulled from within the images themselves, titles and source URLs. Helpfeel said no payment card information was exposed.

The company said it discovered the intrusion around September 11 and 12, cut off the attacker's access, patched the underlying vulnerability and brought in outside forensic investigators before disclosing the breach publicly on September 16. It is requiring affected users to change their passwords, warning them to watch for phishing attempts that could exploit the stolen data, and has temporarily disabled viewing of some images where exposed metadata could otherwise let someone locate private content.

Security researchers have flagged the OCR text and EXIF location data bundled into the leaked image metadata as unusually sensitive for a breach of this kind, since screenshots and photos often capture information — addresses, account numbers, private conversations — that users never intended to expose, and that data was gathered automatically rather than typed into a form a user might have thought twice about. Gyazo has not said whether the stolen data has appeared for sale or been published elsewhere, and no group has publicly claimed responsibility for the intrusion.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →