Pierluigi Paganini
September 18, 2026

Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server.
“We have confirmed that approximately 23.62 million records containing data related to Gyazo users were disclosed without authorization.” notice of data breach.
Gyazo is a popular cross-platform tool for capturing screenshots, GIFs and short screen recordings and instantly sharing them through links. The incident highlights the risks of vulnerabilities in systems that handle and store user-generated content.
Helpfeel said this week that it recently discovered unauthorized access to its Gyazo servers. The threat actor exploited a vulnerability in the image upload server on September 11 and was able to run malicious commands.
The attacker was locked out the following day, but had already accessed a database containing about 23.6 million user records.
The stolen data includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information.
Helpfeel said payment card data was not affected.
“Helpfeel Inc. (Head Office: Kyoto, Japan; Representative Director and CEO: Isshu Rakusai; hereinafter “Helpfeel”) has confirmed that Gyazo, our image-sharing service, was subject to unauthorized access by a third party, resulting in the unauthorized disclosure of user information and certain metadata associated with uploaded images.” continues the notice of data breach. “We have blocked all access routes used in the incident and have completed remediation of the vulnerability that was exploited. We continue to prioritize measures to prevent further harm while investigating the scope and impact of the incident.”
Helpfeel confirmed that exposed data may include names or nicknames, email addresses, password hashes, user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile information, language preferences, registration and last login dates and times, subscription plans, billing status, and usage statistics.
The affected records also include anonymous accounts without registered email addresses. Helpfeel said no payment information, including credit card numbers, was exposed. The investigation is still ongoing, so further details may emerge.
The company also confirmed that about 490 million image metadata records were exposed, mainly linked to images uploaded in or before January 2019. Metadata from another 2.4 million images was also accessed through specific searches. The exposed information may include image IDs, upload IP addresses, User-Agent data, EXIF location information, OCR text, image titles, source URLs, other metadata and hashed passphrases for private images.
Some of this information could potentially be used to reconstruct Gyazo image URLs and access images without authorization. The company temporarily disabled access to some images and confirmed that a list of private images was obtained. It has not confirmed that image files themselves were stolen, but cannot rule out that some private images were viewed. No unauthorized disclosure has been confirmed in Helpfeel or Cosense systems.
“We plan to send notifications regarding this incident to the registered email addresses of Gyazo users who may have been affected. We are currently working to identify users whose information was disclosed without authorization and will determine which users to notify based on the progress of our investigation.” continues the notice. “For users we are unable to reach by email, such as those with anonymous accounts without a registered email address or similar contact information, we plan to provide notifications through the Gyazo web interface.”
The investigation is still ongoing, and the company will publish updates if further information emerges. The company is asking all Gyazo users to change their passwords, especially if the same or a similar password is used on other services. Users should also stay alert for suspicious emails, messages or other communications that may attempt to exploit the breach.
These precautions are intended to reduce the risk of further account compromise or phishing attacks.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Data Breach)