Gyazo, the popular image-sharing and screenshot platform, has suffered a major data breach after attackers exploited a vulnerability in its image upload server. According to Helpfeel, the company operating Gyazo, the unauthorized access happened on September 11, 2026. The attackers were able to gain access to the system and execute arbitrary commands. The company detected suspicious activity that same evening and started investigating the incident. By the early hours of September 12, the identified access routes had been blocked and the unauthorized connections were terminated. However, the attackers had already accessed Gyazo’s database before they were removed from the system.
The investigation confirmed that approximately 23.62 million records containing information related to Gyazo users were exposed without authorization. The affected information varies from user to user and can include names or nicknames, email addresses, password hashes, user IDs, device IDs and login session IDs. Some users who connected their X accounts may also have had X integration tokens exposed, while users who signed in through Google may have had their Google SSO email addresses included. Profile information, language preferences, registration and login dates, subscription plans, billing status and usage statistics were also among the information involved. The company said the figure includes records from anonymous accounts as well.
Helpfeel has confirmed that payment information was not exposed in the incident. This includes credit card numbers and other payment method information. However, password hashes were included in the exposed data, although the company confirmed that passwords themselves were not exposed in plain text. Gyazo has asked all users to change their passwords as a precaution, especially if they have reused the same or a similar password on another service. The company is also warning users to stay alert for suspicious emails, messages or links that may attempt to take advantage of the breach. Potentially affected users will be contacted through their registered email addresses or through the Gyazo service interface.
The incident also involved a much larger amount of image-related metadata. Helpfeel said approximately 490 million metadata records connected mainly to images registered in or before January 2019 were exposed. An additional approximately 2.4 million image metadata records were obtained through specific filtering conditions. The exposed metadata may include image IDs, upload IP addresses, User-Agent information, EXIF location data when available, OCR text extracted from images, image titles, source URLs and hashed passphrases used for private images. Because image IDs are used to construct Gyazo image URLs, the exposed information could potentially allow unauthorized access to some images.
Gyazo has temporarily disabled access to some images to reduce the possibility of further harm. The company also confirmed that attackers obtained a list identifying private images. Helpfeel has not confirmed that image files themselves were stolen, but it said it cannot completely rule out the possibility that some private images may have been viewed. Its investigation into the incident is still continuing with external specialists. So far, the company has not found evidence that image data was lost because of the unauthorized access. Helpfeel also said that its other services, including Helpfeel and Cosense, have separate system architectures and have not been found to have suffered unauthorized data exposure from this incident.
Following the breach, Helpfeel said it has fixed the exploited vulnerability and blocked the access routes used by the attackers. The company is continuing a forensic investigation to understand the full scope and impact of the incident and is preparing further notifications for affected users and relevant authorities. Helpfeel has also reported the incident to Japan’s Personal Information Protection Commission. The company said it will strengthen authentication, authorization and access controls, improve monitoring and auditing, and review its security development practices to reduce the chance of a similar incident happening again. Gyazo users are advised to change their passwords and remain cautious about suspicious communications connected to the breach.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news