Posted in

Gyazo Data Breach Exposes 23.6 Million User Records and 490 Million Image Metadata Records

A security breach at Gyazo, an image-sharing service operated by Helpfeel, has exposed approximately 23.62 million user records, including email addresses and password hashes.

The incident also exposed around 490 million image metadata records, most of which relate to images registered in January 2019 or earlier.

According to Helpfeel, the exposed information includes image IDs used to create Gyazo URLs. Because those IDs form an important part of the links used to access images, the company warned that some images could potentially be viewed without authorization.

Helpfeel has temporarily restricted access to some affected images while it investigates the incident.

How the Gyazo Breach Happened

The attacker reportedly gained access by exploiting a vulnerability in Gyazo’s image-upload server.

After obtaining access, the attacker was able to execute arbitrary commands on Helpfeel’s systems and subsequently access the Gyazo database.

The company has not disclosed the exact nature of the vulnerability or provided technical details about how it was exploited.

Helpfeel said it detected suspicious activity on the evening of September 11, 2026, Japan time.

By the early hours of September 12, the company said it had blocked the identified access routes, terminated the attacker’s connections, and fixed the exploited vulnerability.

A forensic investigation by external specialists is now underway.

User Information Exposed

The 23.62 million figure represents database records rather than the number of individual people affected.

Helpfeel said the total includes anonymous accounts that may not have a registered email address. The company is still determining how many users had their personal information exposed.

Depending on the account, exposed records may contain:

  • Name or nickname entered by the user
  • Email address
  • Password hash
  • User ID
  • Device ID
  • Login session ID
  • X integration token, if connected
  • Google SSO email address, if configured
  • Profile information
  • Language preference
  • Account registration date and time
  • Last login date and time
  • Subscription plan
  • Billing status
  • Usage statistics

The company said payment information, including credit card numbers, was not exposed.

Helpfeel also said it reviewed the compromised authentication information and implemented measures including invalidation and access restrictions. However, it has not publicly specified which authentication data was invalidated.

Password Changes Recommended

Helpfeel has asked all Gyazo users to change their passwords.

Users are also being advised to change their passwords on other services if they have reused the same or a similar password elsewhere.

This is particularly important because the compromised database reportedly contained password hashes. While a password hash does not directly reveal the original password, weak or reused passwords may be vulnerable to offline cracking attempts depending on the hashing method and other security controls.

Users should also be cautious about unexpected emails, messages, or login notifications that could be related to the incident.

Image Metadata Also Exposed

The breach goes beyond account information.

Approximately 490 million image metadata records were exposed, with most associated with images registered in January 2019 or earlier.

Helpfeel said this dataset represents roughly 14.4% of its image-related data.

The exposed metadata can include:

  • Image ID
  • Upload IP address
  • User-Agent information
  • EXIF location data, when present
  • OCR-extracted text
  • Image title
  • Source URL
  • Other image metadata
  • Hashed passphrase for private images

A separate dataset containing approximately 2.4 million additional image records was also accessed using what Helpfeel described as specific filtering criteria.

The company has not explained what criteria were used, whether the two datasets overlap, or whether the second dataset contains newer images.

Leaked Image IDs Could Create Privacy Risks

Every Gyazo capture is associated with a unique 32-character image ID that forms part of its URL.

Gyazo’s privacy model traditionally relies heavily on the secrecy of that URL. Images are generally not publicly searchable, but anyone who obtains the direct link may be able to view the corresponding capture, depending on its privacy settings.

This makes the exposure of image IDs particularly significant.

Free accounts can view only their 10 most recent captures through the Gyazo website, but older captures are not necessarily deleted and can remain accessible to anyone who possesses the relevant URL.

The company has temporarily disabled viewing of some images while investigating the incident.

Helpfeel said its investigation has not identified evidence that image data itself was lost. However, the attacker obtained information identifying private images, and the company said it cannot rule out the possibility that some private images were viewed.

Private and Password-Protected Images

Gyazo offers different privacy options, including an “Only me” setting and password protection for certain paid accounts.

The “Only me” option is designed to prevent others from viewing an image even if they know its URL, while password-protected images require an additional password.

Helpfeel has not specified which types of private images may have been affected or whether the attacker successfully accessed any of them.

The company also has not explained how potentially affected users can determine whether their individual images were included in the exposed datasets.

OCR Data Could Contain Sensitive Information

Another concern involves OCR data.

Gyazo offers an optical character recognition feature that extracts text from uploaded screenshots and makes that text searchable.

According to the service’s documentation, OCR is a paid feature that users can enable for their accounts. Once activated, it can process images stored within the account.

Because OCR results may contain text from screenshots, documents, messages, credentials, addresses, or other sensitive material, exposure of this information could potentially create additional privacy risks.

Helpfeel said OCR results are intended to be visible only to the account holder.

Incident Was Initially Described as Maintenance

The breach investigation also explains why Gyazo users may have experienced image-loading problems in September.

After detecting suspicious activity, Gyazo temporarily restricted image delivery. Public service notices initially described the disruption as maintenance and did not disclose the security incident.

On September 14, the company suspended delivery of some images and again described the issue as emergency maintenance.

New image uploads resumed on September 15, although some existing images remained unavailable.

Helpfeel said it confirmed the data exposure on September 14 and reported the incident to Japan’s Personal Information Protection Commission on September 15.

The company publicly disclosed the breach on September 16.

Other Helpfeel Services Not Affected

Helpfeel said its other products, Helpfeel and Cosense, operate on separate systems.

At this stage, the company said it has found no evidence that data from those services was exposed as part of the Gyazo incident.

However, Gyazo images embedded within those products may remain unavailable while the company’s image-delivery systems are restricted.

What Gyazo Users Should Do

Users should take several precautionary steps following the breach:

  1. Change the Gyazo password immediately.
  2. Change reused or similar passwords on other services.
  3. Be alert for phishing emails and suspicious messages.
  4. Avoid clicking unexpected login or password-reset links.
  5. Review connected third-party accounts and integrations.
  6. Monitor accounts for unusual login activity.
  7. Consider sensitive information that may have appeared in uploaded screenshots.

Helpfeel said it will contact users it identifies as affected. For anonymous accounts, the company plans to provide notices through the Gyazo website.

The company is continuing its forensic investigation and said additional information will be provided as the investigation progresses.

Users with questions about the incident can contact Helpfeel through Gyazo’s support channels.

Leave a Reply

Your email address will not be published. Required fields are marked *