Gyazo breach exposes 23.62 million user records and image metadata

Helpfeel, the company behind the Gyazo screenshot and image-sharing service, says unauthorized access to Gyazo exposed approximately 23.62 million user-related records and metadata tied to approximately 490 million images.

The incident began on Sept. 11, 2026, according to Helpfeel’s Sept. 16 notice. The company said a third party exploited a vulnerability in Gyazo’s image upload server, gained unauthorized access to systems, and executed arbitrary commands. Helpfeel said suspicious activity was detected that evening and the identified access routes were blocked by the early hours of Sept. 12.

The company’s investigation is still ongoing. The 23.62 million figure refers to records, not a confirmed count of unique individuals. Helpfeel said the count includes anonymous accounts with no registered email address, and it is still determining how many individuals had personal information disclosed.

What Gyazo says was exposed

Helpfeel says the exposed user information varies by account. The data may include names or nicknames entered by users, email addresses, password hashes, user IDs, device IDs, login session IDs, profile information, language preferences, registration and last-login dates, subscription plan, billing status, and usage statistics.

For connected accounts, the exposed data may also include X integration tokens and email addresses associated with Google SSO. Helpfeel said it has already implemented measures such as invalidation and restrictions for authentication-related information where appropriate.

Helpfeel says payment information, including credit card numbers and other payment method information, was not disclosed without authorization.

Why the image metadata raises the risk

The breach was not limited to account fields. Helpfeel says approximately 490 million metadata records tied primarily to images registered in or before January 2019 were disclosed without authorization. Another approximately 2.4 million image metadata records were retrieved under separate filtering criteria.

The exposed metadata may include image IDs used to construct Gyazo image URLs, source IP addresses, User-Agent data, EXIF location data when present, OCR text extracted from images, image titles, source URLs, hashed passphrases for private images, and other related information.

That metadata creates a separate concern from the account breach. Helpfeel says the exposed information could be used to access and view corresponding images without authorization. The company has temporarily disabled viewing of some images to reduce further harm and says it cannot rule out that some private images may have been viewed by the third party.

What affected users should do now

Helpfeel is asking all Gyazo users to change their Gyazo passwords. The immediate priority is to prevent password reuse from turning one breach into account takeovers elsewhere.

  • Change the Gyazo password directly through Gyazo, not through links in unexpected emails or messages.
  • Change any same or similar password used on another service, starting with email, cloud storage, social accounts, financial accounts, and work systems.
  • Use unique passwords for every account. A password manager can make replacements easier to manage.
  • Enable multifactor authentication on high-value accounts where available, especially email and work accounts.
  • Watch for phishing messages that mention the Gyazo incident, password resets, suspicious activity, image access, or account verification.
  • Review old Gyazo links that may contain sensitive screenshots, documents, receipts, customer data, internal tools, location data, or work-related information.

General guidance from CISA supports using multifactor authentication because it can reduce the risk of account access when a password is compromised. FTC consumer guidance also warns that phishing emails and texts often try to steal passwords or push people into opening malicious links and attachments.

What organizations should review

For businesses, the exposure is broader than a personal password reset. Gyazo is often used for screenshots, GIFs, and short recordings. If those captures included customer tickets, software errors, API keys, internal URLs, employee information, or confidential documents, the metadata and possible image access issue may require a review.

Teams that used Gyazo in documentation, support workflows, bug reports, knowledge bases, or chat threads should identify sensitive uploads and decide whether credentials, links, tokens, or internal references need to be rotated or removed. Screenshots can contain more than the intended subject, especially when browser tabs, sidebars, command lines, dashboards, or notifications are visible.

Current status of the investigation

Helpfeel says it completed initial response measures and remediated the exploited vulnerability on Sept. 12. On Sept. 14, the company confirmed that Gyazo information had been disclosed without authorization and implemented precautionary measures, including suspending image delivery. On Sept. 15, Helpfeel said it resumed delivery of images uploaded after countermeasures were completed and submitted a report to Japan’s Personal Information Protection Commission.

In a Sept. 18 Japanese-language update, Helpfeel said it had not confirmed information leakage from Helpfeel or Cosense systems and had not confirmed traces of unauthorized access or attacks against those services. The company also said some images displayed through those services may be unavailable because of Gyazo image delivery restrictions.

Helpfeel says potentially affected users will be notified by registered email address or, where email contact is difficult, through the Gyazo service interface. The company says it will publish updates if its investigation identifies additional facts.

Frequently asked questions

Did the Gyazo breach expose plaintext passwords?

Helpfeel says password hashes were exposed, not plaintext passwords. The company is still asking all Gyazo users to change their passwords and to change reused or similar passwords on other services.

Were payment card numbers exposed in the Gyazo breach?

Helpfeel says it has not confirmed unauthorized disclosure of payment information, including credit card numbers or other payment method information.

Were private Gyazo images exposed?

Helpfeel says image metadata was exposed and a list identifying private images was obtained. The company has not ruled out that some private images may have been viewed by the third party.

What should Gyazo users do now?

Affected users should change their Gyazo password, replace any reused or similar passwords on other services, avoid links in suspicious messages, and review old Gyazo uploads that may contain sensitive information.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email