VYPR
breachPublished Sep 17, 2026· 1 source

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Image-sharing service Gyazo, operated by Helpfeel, has disclosed a significant data breach affecting 23.62 million user records and nearly half a billion image metadata records.

Helpfeel, the operator of the popular image-sharing service Gyazo, has confirmed a substantial data breach that exposed approximately 23.62 million user records. The compromised data includes sensitive information such as email addresses and password hashes. In addition to user credentials, the breach also resulted in the exposure of around 490 million image metadata records, primarily pertaining to images uploaded before January 2019. These exposed metadata records include the unique IDs that form the basis of Gyazo's image links.

The company stated that the exposed image IDs could potentially be used to view images without authorization, prompting Gyazo to temporarily disable the viewing of some affected images. Helpfeel has urged all Gyazo users to immediately change their passwords and to update passwords on any other services that use the same or similar credentials. Users have also been advised to remain vigilant for suspicious emails or communications related to the incident.

According to Helpfeel, the attacker gained initial access through a vulnerability in Gyazo's image upload server, which allowed them to execute arbitrary commands on Helpfeel's systems and subsequently access Gyazo's database. The company has not yet disclosed the specific nature of the vulnerability exploited. Importantly, Helpfeel has stated that no payment information, including credit card numbers, was compromised in the breach.

The exposed user records may contain a variety of information, varying by user, including names, email addresses, password hashes, user IDs, device IDs, login session IDs, X (formerly Twitter) integration tokens, Google single sign-on email addresses, profile information, language preferences, registration and last login dates, subscription plan details, and billing status. The 23.62 million figure represents the total number of records, which includes anonymous accounts without registered email addresses, and Helpfeel is still determining the exact number of individuals whose personal information was compromised.

Helpfeel has indicated that it has reviewed the exposed authentication data and implemented necessary measures, including invalidation and restrictions, though it has not specified which particular data items were affected. Gyazo typically employs a verification code system for logins from new IP addresses, but it remains unclear whether the exposed session IDs are still valid. The company also noted that while Gyazo captures are private until their link is shared, and the image IDs are designed to be unguessable, the exposure of these IDs could pose a risk.

The affected metadata records, comprising about 14.4% of Helpfeel's image-related data, are predominantly for images registered before January 2019. An additional 2.4 million images had their metadata extracted using specific filtering criteria, though the company has not detailed these criteria or whether there is an overlap with the earlier set. The exposed metadata fields include Image IDs, IP addresses used for uploads, User-Agent strings, EXIF location data, OCR text, source URLs, and hashed passphrases for private images.

Helpfeel first detected suspicious activity on September 11th, Japan time, and by the early hours of September 12th, had blocked identified access routes and severed the attacker's connections, patching the vulnerability the same day. The company initially attributed image loading issues to maintenance, only confirming the data exposure on September 14th. It reported the incident to Japan's Personal Information Protection Commission on September 15th and published its public notice on September 16th. A forensic investigation is ongoing, and Helpfeel plans to notify affected users directly, with notices for anonymous accounts posted on their website.

Synthesized by Vypr AI