Gyazo, an image-sharing service operated by the Kyoto-based company Helpfeel, recently suffered a significant security breach. The incident exposed approximately 23.62 million user records, including email addresses and password hashes, as well as around 490 million image metadata records. These metadata records encompass image IDs that form part of Gyazo's image links, allowing unauthorized access to images. Helpfeel has responded by temporarily disabling the viewing of some images to mitigate further unauthorized access.

The breach was facilitated by a vulnerability in Gyazo's image upload server, enabling attackers to execute arbitrary commands and access Gyazo's database. Although Helpfeel has not disclosed the specific nature of the flaw, they have confirmed that no payment information was compromised. The company is still assessing the full extent of personal data exposure, noting that the affected user records may include accounts without registered email addresses.

Helpfeel has urged all Gyazo users to change their passwords and monitor their accounts for suspicious activity. The company has also taken steps to invalidate certain authentication data and apply restrictions. Despite these measures, the validity of exposed session IDs remains unclear.

The impacted image metadata largely pertains to images registered in January 2019 or earlier, constituting about 14.4 percent of Helpfeel's image-related data. An additional set of 2.4 million images was also affected, though the details of this extraction process remain unspecified. While Helpfeel continues its investigation, they have assured that no loss of image data has been detected.

The breach prompted Helpfeel to report the incident to Japan's Personal Information Protection Commission and initiate an external forensic investigation. Communications with affected users will occur via email for those identified, with notices on Gyazo's website for users of anonymous accounts. Helpfeel's other products, including Helpfeel and Cosense, are hosted on separate systems and were not affected by the breach.