Helpfeel Confirms Gyazo Data Breach Exposed 23.62 Million User Records and 490 Million Image Entries
Helpfeel has confirmed that an intruder reached the database behind Gyazo, its image-sharing service, and removed roughly 23.62 million user records along with about 490 million image metadata entries. The Kyoto-based company disclosed the Gyazo data breach on September 16, five days after an attacker exploited a vulnerability in the service's image upload server. Payment card numbers and other payment data were not exposed.
The attacker used the upload server flaw to run arbitrary commands on Helpfeel's systems. Helpfeel detected unusual activity that evening and had blocked the intrusion routes and patched the vulnerability by the early hours of September 12. An investigation on September 14 confirmed that Gyazo data had left the company's systems. Helpfeel notified Japan's Personal Information Protection Commission on September 15 and published its disclosure notice the next day.
Containment and exfiltration did not happen in the same window. The attacker's routes were cut within hours of detection, but the data had already been copied out of the network before the underlying flaw was fixed.
What the 23.62 Million User Records Contain
The leaked user data covers a wide set of fields:
- Names or nicknames as entered by the user
- Email addresses, including Google SSO email addresses
- Password hashes
- User IDs, device IDs and login session IDs
- X (Twitter) integration tokens
- Profile information
- OCR text extracted from some captured screenshots
The 23.62 million figure counts records rather than individuals. Several records can belong to one account, and the total includes anonymous accounts that never registered an email address, so Helpfeel is still working out how many people are affected. Gyazo's registered user base is roughly 23 million, which places the leaked record count close to the size of the entire service.
Session and device identifiers widen the damage beyond email addresses. Those values give an attacker a way to tie records to particular devices, and any login session that has not expired could be reused. X integration tokens carry a different kind of risk, because they can expose a linked social account rather than a Gyazo account.
Payment information stayed out of the dataset, which limits the direct financial exposure. No card numbers, bank details or billing records appeared in either dataset. The credential material is the larger problem.
Image Metadata and the Link ID Problem
The second set is larger. About 490 million metadata entries relate to uploaded images, most of them from January 2019 or earlier, and they make up roughly 14.4 percent of all image-related data. A separate batch of about 2.4 million metadata records, gathered under different conditions, was exposed as well.
Those entries carry image IDs, the IP address and User-Agent string of the uploader, EXIF location data, OCR text, image titles, referring URLs and flags marking private images. Image IDs are the sensitive part. Gyazo builds share links directly from them, and at the default privacy setting a link is the only thing protecting a capture from anyone who has the URL.
The 14.4 percent figure also draws a boundary around the damage. It means the bulk of image-related metadata in Gyazo's systems, roughly 85 percent of it, was not confirmed as exfiltrated, so the exposure is concentrated in older records rather than the full image library.
OCR text deserves separate attention. Gyazo extracts text from screenshots so that they become searchable, which means captured OCR strings can include whatever happened to be on screen at the time: chat messages, order confirmations, work documents, password fields, partial code. Metadata that began as a search index can therefore read like a content leak.
Helpfeel has said images covered by the exposed metadata could be reached without authorization, and that some private captures may have been viewed by a third party.
What Gyazo Users Should Do
Password hashes left Helpfeel's systems in place of plaintext passwords, so for anyone caught in the Gyazo data breach the immediate risk depends on the hashing method used and whether the stored values can be cracked. Changing the Gyazo password, and any password reused on other services, is the first step. Users who linked their Twitter account to Gyazo should also review the apps authorized in their X settings and remove any they do not recognize.
For private captures uploaded in or before January 2019, the working assumption should be that the image ID is known to the attacker. Age is the awkward part of this dataset. A cutoff at January 2019 points to captures that many users have long forgotten: old screenshots, expired links, abandoned projects. Those are the images least likely to be checked after a breach notice, and the ones whose URLs have been sitting in chats and documents for years.
Revisiting the privacy setting on any capture that still needs to stay private, or deleting it, closes that exposure.
Timeline of the Gyazo Data Breach
| Date | Event |
|---|---|
| September 11, 2026 | Attacker exploits a vulnerability in Gyazo's image upload server and runs arbitrary commands |
| September 12, 2026 (early hours) | Intrusion routes blocked and the flaw patched |
| September 14, 2026 | Investigation confirms Gyazo data was exfiltrated |
| September 15, 2026 | Incident reported to Japan's Personal Information Protection Commission |
| September 16, 2026 | Helpfeel publishes its disclosure notice |
Helpfeel's response was tight by breach standards. The intrusion ran for less than a day before containment, and the gap between confirming exfiltration and telling the public was two days. What shapes the risk is the age of the affected records, not the speed of the disclosure.
Why this matters
The Gyazo data breach puts a number on something users rarely think about: the metadata attached to every screenshot they upload. A password hash can be rotated. An image ID that has been the only protection on a private capture since 2019 cannot. Helpfeel has patched the upload flaw and cut off the intrusion, but the affected records reach back to January 2019 or earlier, and the company has not yet determined how many individuals the 23.62 million records represent. Until that count is settled, the cleanup rests with users rotating credentials and revisiting old link-protected captures.
AI-generated image.
Related Articles
- Framework Data Breach: Metabase Zero-Day Exposed Every Customer's Details
- Carhartt data breach exposes 12.9M accounts after a refused $3.3M ransom
- Brinks Home Data Breach: ShinyHunters Publishes 41GB
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.