Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
- ID
- 25597
- Status
- summarized
- Published
- 17 Sep 2026, 3:30 PM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 18 Sep 2026, 12:54 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Gyazo, Kyoto-based Helpfeel's image-sharing service, suffered a breach exposing 23.62 million user records (emails, password hashes, session IDs, X/Twitter integration tokens, Google SSO emails) and 490 million image metadata records. The attacker exploited a vulnerability in Gyazo's image upload server, ran arbitrary commands, and accessed the database; image IDs in the metadata could be used to view private images without permission, and Helpfeel has temporarily disabled viewing of some.
Why it matters
If you have a Gyazo account, change your password everywhere you reused it and revoke any X/Twitter or Google SSO integrations. If you embed Gyazo links in documentation, apps, or client deliverables, those images may have been accessible to the attacker via exposed image IDs—audit where you've used Gyazo captures containing sensitive content.
Discussion angle
The breach highlights a recurring pattern: session IDs and integration tokens stored in a database with unclear invalidation—worth discussing how your own app handles token rotation and whether session IDs in your DB are treated as compromised-in-breach or remain valid after an incident.