Gyazo, a cloud-based screenshot and screen-recording tool operated by Helpfeel, disclosed the breach in a statement published earlier this week. The platform is especially popular in gaming communities and claims 23 million users worldwide, who have submitted over 3.1 billion media items.
According to the company, the incident occurred on September 11, allowing attackers to access its database and obtain approximately 23.62 million user records. The company detected suspicious activity on September 12 and fixed the vulnerability, but the data had already been stolen.
The exposed data varies per user and may include names or nicknames, email addresses, password hashes, user and device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, subscription information, billing status, and usage statistics.
Additionally, the breach exposed 490 million image metadata records, most associated with images uploaded before January 2019. These metadata include image IDs used to construct image URLs, upload IP addresses, User-Agent strings, EXIF location data, OCR-extracted text, image titles, source URLs, and hashed passphrases for private images. Helpfeel noted that image IDs could potentially be used to access the corresponding content, and the company has temporarily disabled access to files whose records were exposed. The hackers also obtained a list identifying private images, and the company cannot rule out that some were viewed.
Gyazo has taken the platform offline for maintenance as a preventive measure. The company is notifying affected users directly and conducting an investigation with external experts. Authorities have been contacted. No evidence was found that data was deleted, and Helpfeel's other services (Helpfeel and Cosense) were not affected.
All Gyazo users are advised to change their passwords on the service and on other platforms where they use the same credentials, and to remain alert for suspicious communications.