Gyazo has confirmed a major data breach after an attacker exploited a vulnerability in the image-sharing service’s upload server, executed arbitrary commands and gained access to its database, exposing approximately 23.62 million user records and 490 million image metadata records.
Helpfeel, the Japanese company behind Gyazo, said the attacker gained unauthorized access on Sept. 11, 2026. The company detected suspicious activity later that evening and terminated the unauthorized connections by the early hours of Sept. 12.
The exposed user information potentially includes email addresses, password hashes, login session IDs, device identifiers and integration tokens. The breach also exposed metadata capable of constructing Gyazo image URLs, creating the possibility that corresponding screenshots, GIFs, videos and other uploaded content could be accessed.
Helpfeel said it has also confirmed that the attacker obtained a list identifying private images and cannot rule out the possibility that some private content was viewed.
Attacker exploited Gyazo image upload server
Helpfeel said the intrusion began when a third party exploited a vulnerability in Gyazo’s image upload server to gain unauthorized access and execute arbitrary commands.
The attacker subsequently accessed Gyazo’s database, allowing user information and metadata associated with uploaded images to be disclosed without authorization.
Helpfeel detected suspicious activity on Sept. 11 and began investigating the incident. By early Sept. 12, the company said it had blocked the identified access routes, terminated connections established by the attacker and remediated the exploited vulnerability.
The company has not publicly provided additional technical information about the vulnerability or explained whether it was a previously unknown security flaw.
23.62 million user records exposed
Helpfeel’s investigation confirmed the unauthorized disclosure of approximately 23.62 million records containing information associated with Gyazo users.
Depending on the account, the exposed information can include names or nicknames, email addresses, password hashes, user IDs, device IDs, login session IDs and profile information.
Additional fields can include X integration tokens for connected accounts, email addresses associated with Google single sign-on, language preferences, registration and last login timestamps, subscription plans, billing status and usage statistics.
Helpfeel said the types and amount of information exposed vary between users.
The 23.62 million figure should not be interpreted as the confirmed number of individual victims. Helpfeel said the dataset includes records belonging to anonymous accounts without registered email addresses and is still determining how many individuals had personal information exposed.
The company confirmed that payment information, including credit card numbers, was not compromised.
Helpfeel said it reviewed the authentication-related information involved in the breach and implemented measures including invalidation and restrictions intended to prevent misuse.
490 million image metadata records stolen
The scale of the image metadata exposure significantly expands the potential impact of the breach.
Helpfeel confirmed that approximately 490 million metadata records were disclosed, primarily relating to images registered in or before January 2019. The company said those records represent approximately 14.4% of all Gyazo image-related data.
The attacker also separately retrieved metadata associated with approximately 2.4 million images using specific filtering criteria.
The compromised metadata can include image IDs, source IP addresses, user-agent information, image titles, source URLs and EXIF location data embedded in uploaded images.
It can also contain text extracted from images using optical character recognition and hashed passphrases associated with private images.
Those fields are particularly sensitive because Gyazo is commonly used to rapidly capture and share screenshots and other visual content. OCR data could expose text visible inside captured images, while EXIF information could reveal location information when it was present in the original file.
Exposed IDs could be used to access Gyazo images
Helpfeel warned that the compromised metadata includes image IDs used to construct Gyazo image URLs.
According to the company, those identifiers could potentially allow a third party to construct URLs and access corresponding images without authorization.
Helpfeel temporarily disabled viewing of some images as a precaution while investigating the exposure.
The company also confirmed that the attacker obtained a list identifying private images. Helpfeel said it cannot rule out the possibility that the attacker viewed some of those images and is continuing to investigate.
Helpfeel has not found evidence that image data itself was deleted or lost as a result of the intrusion.
The distinction between stolen metadata and direct theft of the underlying image files is important. Helpfeel has confirmed the metadata disclosure and potential ability to access corresponding images, but has not said that all images associated with the exposed metadata were downloaded by the attacker.
Gyazo urges all users to change passwords
Helpfeel is asking all Gyazo users to change their passwords as a precaution following the breach.
Users who reused the same or similar passwords on other services are also being urged to change those credentials.
The company is preparing notifications for users whose information may have been affected. Registered users will receive notifications by email where possible, while Helpfeel plans to notify anonymous users through the Gyazo web interface when direct contact information is unavailable.
Helpfeel also warned users to remain alert for suspicious emails, messages and other communications that could attempt to exploit information exposed in the breach.
The company said its Helpfeel and Cosense services use architectures separate from Gyazo and that its investigation has not identified unauthorized disclosure from those systems as a result of the incident.
Japanese regulator notified as investigation continues
Helpfeel confirmed the unauthorized disclosure on Sept. 14 and temporarily suspended some image delivery while implementing additional protections.
On Sept. 15, the company introduced further measures, resumed delivery of newly uploaded images after addressing the unauthorized access and reported the incident to Japan’s Personal Information Protection Commission.
Helpfeel publicly disclosed the breach on Sept. 16 and said external forensic specialists are continuing to investigate its scope and impact.
The company is also assessing notification requirements in other jurisdictions and plans to submit additional reports to regulators where required.
Helpfeel said it will review authentication, authorization and access controls, expand monitoring and auditing, improve secure development and review practices, and examine its other services for similar vulnerabilities.
The investigation remains ongoing, meaning the confirmed scope could change. For now, the combination of approximately 23.62 million exposed user records, 490 million image metadata records and information potentially capable of reconstructing image URLs makes the Gyazo incident one of the more significant image-sharing platform breaches disclosed in 2026.












