Image depicting a hand on a scanner

Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack | Daily Reports Online

Share


  • Helpfeel confirmed a Sept 11 breach compromising 23.62M records tied to Gyazo users
  • Stolen data includes PII, login/session IDs, Google SSO tokens, and 490M image metadata records
  • Payment info safe, but private images may have been exposed; viewing disabled pending investigation

A Japanese customer-support and knowledge-base company suffered a cyberattack recently in which it lost millions of user records, including personally identifiable information (PII) and, possibly, customer photographs.


The company in question is called Helpfeel. It is an established organization with more than 200 employees, operating as a combination of a modern help center, intelligent search, and an AI support agent. It runs an image-sharing service called Gyazo. According to a breach notification published earlier this week, the breach happened on September 11, when an unidentified threat actor abused a vulnerability to upload malware, gain access to the service’s servers, and run arbitrary commands on them.


Similar Posts