Gyazo breach exposed 23.62 million user records and 490 million image metadata records
Stock photo
Helpfeel said an intruder accessed Gyazo's database and exposed about 23.62 million user records after exploiting an image-upload server flaw on September 11.
The company's notice lists names, email addresses, password hashes, session IDs and some connected-account tokens among the affected data. Helpfeel said no credit-card or other payment information was exposed.
The count is not people. Helpfeel said the 23.62 million total includes anonymous accounts and it has not finished determining the number of individuals affected.
About 490 million metadata records tied mainly to images registered by January 2019 were also exposed, representing about 14.4 percent of Gyazo's image-related data at the time.
The disclosure is three days old, but its instruction remains active: every Gyazo user should change their password.