Back to Feed
BreachesSep 17, 2026

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Gyazo breach exposes 23.62M user records and 490M image metadata records.

Summary

A security breach at Gyazo, Helpfeel's image-sharing service, has exposed approximately 23.62 million user records, including email addresses and password hashes. Additionally, around 490 million image metadata records were compromised, potentially allowing unauthorized viewing of older images. The attacker gained access via a vulnerability in the image upload server, enabling command execution and database access.

Full text

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records Swati KhandelwalSep 17, 2026Data Breach / Web Security A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said those IDs could be used to view the images without permission, and that it has temporarily disabled viewing of some of them. Helpfeel asked every Gyazo user to change their password and to change it on any other service that uses the same or a similar one. It also asked users to watch for suspicious emails or messages related to the incident. The attacker gained access through a vulnerability in Gyazo's image upload server, ran arbitrary commands on Helpfeel's systems, and accessed Gyazo's database, the company said. It has not said what kind of flaw it was. Helpfeel said no payment information, including credit card numbers, was exposed. The exposed user records can include the following, and the fields present vary from user to user: Name (any text the user entered, such as a name or nickname) Email address Password hash User ID Device ID Login session ID X (formerly Twitter) integration token, if the account was connected Email address used for Google single sign-on (SSO), if connected Profile information Language preference Registration date and time Last login date and time Subscription plan Billing status (no credit card numbers or other payment details) Usage statistics The 23.62 million figure counts records. Helpfeel said they include anonymous accounts with no registered email address, and that they are still working out how many people had their personal information exposed. Helpfeel said it has reviewed the exposed authentication data and taken "the necessary measures, including invalidation and restrictions." It did not say which items were invalidated. Gyazo normally emails a verification code when a login comes from a new IP address, a check that runs at login. Helpfeel has not said whether the exposed session IDs remain valid. Every Gyazo capture gets a link built from a 32-character image ID. Gyazo's help pages say a capture stays private until its link is shared, that anyone who has the link can see it, and that the ID is long enough that a link "can't be guessed." For a capture at the default setting, the link is the only thing protecting it, and the leaked image IDs are the part of the link that makes it unguessable. Free accounts can browse only their 10 most recent captures on Gyazo's site, but Gyazo says older captures are not deleted and remain accessible to anyone with the URL. The affected metadata records are mostly for images registered in January 2019 or earlier and make up about 14.4% of Helpfeel's image-related data, the company said. Metadata for a further 2.4 million images was pulled separately using what Helpfeel called "specific filtering criteria." It has not said what the filter was, whether the two sets overlap, or whether the second set includes newer images. Helpfeel listed these fields, plus other related information: Image ID, the information used to build the image URL IP address used for the upload User-Agent EXIF location data, if the image contained it OCR text extracted from the image Image title Source URL and other metadata Hashed passphrase for private images Helpfeel said it temporarily disabled viewing of some images to prevent further harm, and that its investigation has not found any loss of image data. It has not said which images are disabled, or how a user can tell whether their captures are in the affected sets. The attacker also obtained a list identifying private images, Helpfeel said, and the company said it "cannot rule out the possibility that the third party may have viewed some private images." On Gyazo, a private capture can mean one set to "Only me," which the help pages say cannot be viewed even by someone who knows the link, or one locked with a password. Both settings are available only on paid plans, and Helpfeel has not said which it means or how such images could have been viewed. The OCR text field comes from a Gyazo feature that reads the text in a user's captures, allowing them to search it. Gyazo's help pages describe it as a paid feature that users enable themselves and that then scans all the account's images. The same pages say, "Only you can see OCR results." Helpfeel said it noticed suspicious activity on the evening of September 11, Japan time. By the early hours of September 12, it had blocked the access routes it had identified, cut the attacker's connections, and fixed the vulnerability the same day. While images were failing to load, Gyazo's public notices to users called it maintenance and did not mention the breach. When Helpfeel suspended image delivery on September 14, Gyazo's product-updates page said delivery had been suspended for some images "due to emergency maintenance." After delivery of new uploads resumed on September 15, a second notice said, "Some images remain unavailable due to emergency maintenance." Helpfeel said it confirmed on September 14 that data had been exposed, reported the incident to Japan's Personal Information Protection Commission on September 15, and published its notice on September 16. Outside specialists are now running a forensic investigation, Helpfeel said, and it will email users it identifies as affected, with notices on Gyazo's website for anonymous accounts. It is taking questions about the incident through Gyazo's support form. Helpfeel's other products, Helpfeel and Cosense, run on separate systems, and the company said it has not found any data exposure from them, though Gyazo images shown inside them may not load while its image delivery is suspended. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  data breach, Privacy, Vulnerability, Web Security ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Cou

Indicators of Compromise

  • malware — password hashes

Entities

Gyazo (product)Helpfeel (vendor)SSO (technology)