Popular screenshot-sharing service Gyazo has confirmed a major data breach after attackers exploited a vulnerability in one of its image-upload servers and gained access to its internal database.
The breach exposed approximately 23.62 million user records and metadata linked to around 490 million uploaded images, according to Gyazo operator Helpfeel. The company stressed that the figure represents records, not necessarily 23.62 million individual people.
The incident began on September 11, when an unidentified attacker exploited a vulnerability in Gyazo’s image-upload server. The flaw allowed the intruder to execute arbitrary commands on the system.
Helpfeel detected suspicious activity later that day. By early September 12, it had blocked the access routes used by the attacker, terminated unauthorised connections and fixed the vulnerability.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Password hashes, emails and login data exposed
The compromised user information varies between accounts.
According to Helpfeel, exposed records may contain names, nicknames, email addresses, user IDs, device IDs, login session IDs, profile information, recent login times, subscription plans and billing status. Password hashes, rather than plaintext passwords, were also exposed.
Users who connected their X accounts may also have had X integration tokens exposed. Google Sign-In users could have had their Google SSO email addresses included.
The company said credit card numbers and other payment information were not exposed.
Gyazo has nevertheless advised users to change their passwords. Anyone who reused the same or a similar password elsewhere should change those credentials as well.
Why the 490 million image records matter
The second part of the breach potentially carries an even greater privacy risk.
Attackers accessed around 490 million metadata records, primarily relating to captures registered before January 2019. Another roughly 24 lakh image-metadata records were obtained through separately narrowed searches.
This did not necessarily mean hackers downloaded 490 million screenshots.
Metadata is information stored about a file. In Gyazo’s case, it could include image IDs, upload IP addresses, browser or device information, image titles, source URLs, text extracted from screenshots through OCR and location details contained in EXIF data.
Crucially, the exposed information included image IDs used to construct Gyazo URLs.
Helpfeel acknowledged that this data could potentially allow someone to build the corresponding link and access an affected image without authorisation. The company temporarily disabled access to some captures as a precaution.
Investigators also confirmed that the attacker obtained a list identifying private images. Helpfeel said it cannot yet rule out the possibility that some private captures were viewed.
What metadata, OCR and EXIF actually reveal
A screenshot may look like a simple picture, but modern services can store considerable information alongside it.
OCR, or Optical Character Recognition, converts words visible inside an image into searchable text. A screenshot containing an invoice, password-reset message or internal company dashboard could therefore have sensitive text associated with its metadata.
EXIF data is information embedded in certain image files. Depending on the device and settings, it can contain details such as when an image was created and potentially its geographic location.
This makes metadata valuable even when the original image file itself has not been directly stolen.
Gyazo normally says capture details and OCR information are hidden from other users by default. Its documentation also states that an uploaded image can remain stored indefinitely unless the user manually deletes it.
Image-sharing platforms have faced breaches before
The incident echoes an earlier breach involving image-hosting service Imgur.
Imgur disclosed in 2017 that attackers had stolen email addresses and password hashes belonging to about 17 lakh accounts during a breach that occurred several years earlier. The company subsequently forced affected users to reset their passwords.
The Gyazo incident is more complicated because screenshots can contain information users never intended to preserve as long-term sensitive records.
A quick screenshot of an internal dashboard, customer record, authentication code or private conversation may remain online long after the user has forgotten uploading it.
Helpfeel says its investigation remains ongoing and that it will contact users identified as potentially affected. The company has not confirmed theft of payment-card information or loss of the underlying image files.
However, because exposed metadata may provide paths to some captures, users should treat the incident as more than a conventional email-and-password leak.
What this means for you: Change your Gyazo password immediately and change it anywhere else you reused it. Also review old Gyazo captures and delete screenshots containing personal documents, passwords, financial information or sensitive workplace data.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics