Wire Observer.
Technology

Gyazo breach compromises over 23 million user records and half‑billion image metadata entries

Gyazo breach compromises over 23 million user records and half‑billion image metadata entries

A security incident disclosed by cybersecurity firm Helpfeel on September 11 has revealed that the image‑hosting platform Gyazo suffered a massive data breach affecting roughly 23.6 million user accounts. The compromised information includes personally identifiable details, authentication tokens, and an extensive cache of image‑related metadata.

According to the investigation, attackers accessed user names, email addresses, hashed passwords, login and session identifiers, as well as Google Single Sign‑On tokens tied to Gyazo accounts. While payment data was reportedly untouched, the breach also exposed metadata for approximately 490 million images uploaded to the service, raising concerns about the visibility of private pictures.

Gyazo, which enables users to capture and share screenshots or photos via short URLs, stores both the image files and accompanying metadata such as timestamps, device information, and geolocation tags. The leakage of this metadata could allow malicious actors to infer details about users’ habits, locations, or personal relationships, even if the actual image files remain protected.

In response to the discovery, Gyazo has temporarily disabled image viewing for affected accounts while it conducts a thorough forensic analysis. The company has also urged users to change passwords, review linked Google accounts, and monitor any unusual activity. Helpfeel’s report indicates that the breach was likely the result of unauthorized access to internal databases rather than a vulnerability in the public-facing application.

Cybersecurity experts note that the scale of the incident underscores the risks associated with services that retain large volumes of user‑generated content and metadata. Even when direct financial information is spared, the aggregation of seemingly innocuous data points can create a detailed profile useful for phishing, identity theft, or blackmail.

Regulators in several jurisdictions are expected to examine whether Gyazo’s data‑protection practices complied with applicable privacy laws, such as the EU’s General Data Protection Regulation and California’s Consumer Privacy Act. The company has pledged to cooperate with authorities and to provide affected users with further guidance as the investigation proceeds.

Source: TechRadar
Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related