Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack
PII, image metadata, and possibly personal images, exposed in a large attack on Helpfeel's image-sharing service.
The Helpfeel company, a Japanese support and knowledge-base platform with more than 200 employees, experienced a cybersecurity breach on September 11. The attack exposed 23.62 million user records, potentially compromising personal identifiable information (PII) and private images. The stolen data includes names, emails, password hashes, device IDs, login session IDs, Google Single Sign-On tokens, profile information, language preferences, registration and login dates, subscription plans, and usage statistics.
Payment information, including credit card numbers, remained secure during the incident. However, the attackers gained access to 490 million image metadata records, including image IDs, source IP addresses, user agents, EXIF location data, OCR text, image titles, source URLs, and hashed passphrases. Helpfeel temporarily disabled image viewing to prevent potential harm and is continuing its investigation to determine the extent of the damage caused by the breach.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.