Helpfeel disclosed a breach of its Gyazo image-sharing service that exposed approximately 23.62 million user records, including email addresses and password hashes. The incident also exposed roughly 490 million image-metadata records, primarily associated with images uploaded in January 2019 or earlier.
The metadata included identifiers used in Gyazo image URLs, potentially enabling unauthorized viewing of affected images. Helpfeel temporarily disabled access to certain impacted images and instructed all Gyazo users to reset their passwords, especially passwords reused on other services; the company has not disclosed the intrusion method, breach timeframe, responsible actor, or broader notification details.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
After detecting suspicious activity, Helpfeel blocked identified access paths, terminated the attacker’s connections, and patched the unspecified vulnerability in Gyazo’s image-upload server. The flaw had enabled arbitrary command execution and access to the Gyazo database.
Helpfeel disclosed a breach affecting its Gyazo image-sharing service, exposing approximately 23.62 million user records containing email addresses and password hashes and roughly 490 million image-metadata records. The metadata, primarily for images from January 2019 or earlier, included image-link identifiers that could enable unauthorized viewing; Helpfeel temporarily disabled some affected image views and told users to reset passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcemkd-cirt.mk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.