Treat every Gyazo password as exposed. Helpfeel, the Kyoto company that runs the screenshot and image-sharing service, has told its whole user base to reset credentials after intruders reached its database.
The tally is steep: about 23.62 million account records and roughly 490 million image metadata rows. Payment details, card numbers included, were not part of the haul.
Entry came through a vulnerable image upload server. From there the attacker ran commands on Helpfeel’s systems, worked a path to the Gyazo database, and pulled records out of it. The company has not said what the upload bug was.
Accounts can carry a name, email address, a password hash, user ID, device ID and login session ID. Where users connected third parties, an X integration token or the Google address behind single sign-on may sit in those same rows.
The image data is the quieter problem. Most of those 490 million records describe uploads from January 2019 or older, and they hold the identifiers that compose Gyazo image links. Anyone holding the list can call up pictures that were never meant to be public. Viewing for some of them has been switched off in the meantime.
Two habits matter most now. Rotate the Gyazo password and everywhere a similar one is reused, and read unexpected messages about the incident with suspicion, because a confirmed address list is exactly what phishing campaigns feed on.
