Skip to content
Data breachContained

Gyazo breach exposes 23.6 million user records and 490 million image metadata records

Helpfeel's image-sharing service Gyazo disclosed that an attacker exploited a flaw in its image-upload server to run commands and reach its database, exposing about 23.6 million user records and roughly 490 million image metadata records.

Victim
Gyazo (Helpfeel)
records
23.6M

On 11 September 2026, Helpfeel, the Japanese company behind the popular screenshot and image-sharing service Gyazo, detected suspicious activity on its systems. An attacker had exploited a vulnerability in Gyazo's image-upload server, used it to run arbitrary commands on Helpfeel's infrastructure, and reached the Gyazo database. Helpfeel said it noticed the intrusion on the evening of 11 September (Japan time) and, by the early hours of 12 September, had blocked the identified access routes, severed the attacker's connections and patched the flaw the same day.

The company assessed that roughly 23.62 million user records were exposed, including email addresses and password hashes, alongside approximately 490 million image metadata records β€” mostly for images uploaded in January 2019 or earlier. The exposed metadata included the image identifiers that make up Gyazo image links, login session IDs, integration tokens, OCR-extracted text, and information related to private images.

Session tokens and private-image data raise the stakes

Security researchers noted that the breach was unusually serious not only for its scale but for the type of data involved: exposed session IDs and integration tokens can enable account takeover and access to connected services, while the OCR text and identifiers tied to private images could reveal sensitive content that users never intended to make public.

Helpfeel urged every Gyazo user to change their password β€” and to change it on any other service where they reused it β€” and reported the incident to Japan's Personal Information Protection Commission on 15 September. Because the company detected the intrusion quickly, cut off access and patched the underlying vulnerability within a day, the incident was assessed as contained, though the exposure of hundreds of millions of metadata records left a long tail of risk.

Timeline

  1. Helpfeel notices suspicious activity on the evening of September 11 (Japan time) after an attacker exploits a vulnerability in Gyazo's image-upload server.

  2. By the early hours of September 12, Helpfeel blocks the identified access routes, cuts the attacker's connections and fixes the vulnerability the same day.

  3. Helpfeel reports the incident to Japan's Personal Information Protection Commission and urges all users to change their passwords.

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
  2. cyberinsider.comhttps://cyberinsider.com/gyazo-data-breach-exposed-23-6-million-user-records-and-490m-image-metadata/
  3. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/experts-gyazos-breach-490-million/

Related incidents