The short version
- Helpfeel has expanded the known scope of the Gyazo breach to include about 174 million metadata records tied to previously deleted images.
- The company says about 23.62 million user records were in the previously disclosed scope and that payment information was not exposed.
- Gyazo has blocked the exploited access route, invalidated affected authentication information and resumed service after additional security checks.
The investigation into the Gyazo breach has uncovered a larger metadata exposure than the company initially disclosed. Helpfeel says the incident now includes about 174 million metadata records associated with images that users had deleted, mostly involving content deleted years earlier.
The numbers describe metadata rather than image files
That distinction is important. Helpfeel has not said that 174 million deleted image files were stolen. The figure refers to metadata records associated with deleted content. The company says the corresponding image files are currently inaccessible and that it has not confirmed loss of stored image data as a result of the incident.
The wider investigation also covers approximately 23.62 million user records. Helpfeel’s breakdown identifies about 18.01 million anonymous records without a registered email address and about 5.62 million records associated with users who had registered email addresses. The company says the types and extent of exposed information varied between users and that payment information was not included.
Helpfeel’s security notice says the incident involved unauthorised third-party access to Gyazo and that investigators also identified metadata for about 490 million images mainly uploaded before an earlier cutoff. A smaller set of 2.4 million records obtained through specific filtering criteria remains under investigation.
The access path has been blocked
Helpfeel says it identified the intrusion route and completed remediation of the vulnerability believed to have enabled the attack. The company also invalidated or restricted authentication information where investigators considered it necessary and introduced measures intended to prevent exposed information from being used to view stored images.
The service response has involved more than simply restoring availability. Helpfeel temporarily suspended Gyazo while it performed additional security verification and forensic work. The company later resumed the service after blocking the access path and implementing additional controls.
The breach illustrates why metadata can become a security problem even when the underlying files are not directly exposed.
Metadata can reveal relationships between accounts and content, upload or deletion history and other structural information about a service. Depending on the system, those records can help an attacker understand the environment even when the original files remain inaccessible.
The company is continuing forensic work with external specialists and is coordinating with regulators in Japan and other jurisdictions. It has also described plans for stronger security reviews, external security expertise and additional developer training.
The current scope remains subject to investigation. Helpfeel says it will publish further updates if it confirms additional facts or changes the service recovery plan. For users, the practical response is to treat unexpected messages about the breach with caution, especially requests for passwords, identity verification or downloads.