BleepingComputer reports that Gyazo confirmed a data breach after attackers exploited a server vulnerability and stole 23.6 million user records. Gyazo, operated by Helpfeel, is a cloud-based screenshot and screen-recording tool. The company says the service has 23 million users worldwide, who have submitted 3.1 billion media items.
According to Gyazo, the incident occurred on September 11, 2026. Attackers accessed its database and obtained approximately 23.62 million user records. The company detected suspicious activity on September 12 and fixed the vulnerability, but said the data had already been stolen. Gyazo has taken the platform offline for maintenance.
Gyazo said the exposed data varies by user and may include anonymous account records and metadata from 490 million images, most uploaded before January 2019. The metadata may contain image IDs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Helpfeel said image IDs could potentially provide access to corresponding content, so it disabled access to files with exposed records. Hackers also obtained a list identifying private images, and the company cannot rule out that some were viewed. Gyazo found no signs that data was deleted and no evidence that other Helpfeel or Cosense services were affected.
Comments
0No comments yet. Be the first to comment.