TechRadar News.
Technology

Gyazo hack exposes more than 23 million accounts and nearly 500 million image metadata records

Gyazo hack exposes more than 23 million accounts and nearly 500 million image metadata records

Helpfeel, a cybersecurity company, announced on September 11 that the image‑hosting service Gyazo experienced a large‑scale breach compromising about 23.6 million user accounts. The exposed data consists of personal identifiers, authentication tokens, and a sizable collection of image‑metadata.

The probe found that the intruders obtained usernames, email addresses, hashed passwords, login and session IDs, and Google Single Sign‑On tokens linked to Gyazo accounts. Although payment information appears to have remained intact, the incident also revealed metadata for roughly 490 million images stored on the platform, prompting worries about the exposure of private photos.

Gyazo allows users to take and share screenshots or pictures through short URLs, keeping both the image files and related metadata—like timestamps, device data, and geolocation tags. If this metadata is leaked, attackers could deduce users’ routines, whereabouts, or personal connections, even when the images themselves stay secure.

Following the revelation, Gyazo has briefly blocked image viewing for compromised accounts as it carries out an extensive forensic review. The firm also advises users to reset passwords, check their linked Google accounts, and watch for any suspicious behavior. According to Helpfeel’s findings, the breach probably stemmed from illicit access to internal databases rather than a flaw in the public‑facing service.

Security specialists point out that the magnitude of this breach highlights the dangers inherent to platforms that store massive amounts of user‑generated content and metadata. Even without financial details, the collection of seemingly harmless data can assemble a comprehensive profile that can be exploited for phishing, identity theft, or extortion.

Authorities in multiple regions are likely to review whether Gyazo’s data‑protection measures meet relevant privacy regulations, including the EU’s GDPR and California’s CCPA. Gyazo has committed to working with regulators and to offering additional guidance to impacted users as the probe continues.

Source: TechRadar
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related