Screenshot-sharing service Gyazo has disclosed a major data breach that exposed approximately 23.62 million user-related records and around 490 million image metadata entries, after an attacker exploited a vulnerability in its image upload server to gain unauthorized access to backend systems.[1][7][10]
Kyoto-based Helpfeel, which operates Gyazo, said the incident began on September 11, 2026, when a third party leveraged a flaw in the image upload server to execute arbitrary commands on company infrastructure and ultimately reach the Gyazo database.[7][10][15] The suspicious activity was detected later that evening, and Helpfeel reports that it cut off the intrusion path and applied a fix for the vulnerable component by the early hours of September 12.[7][10] The company publicly disclosed the breach on September 16, noting that its Helpfeel and Cosense services run on separate systems and that no spillover into those platforms has been identified so far.[1][10]
According to Helpfeel’s breach notice and subsequent local media reports, the exposed user information includes names or nicknames, email addresses, password hashes, user IDs, device IDs, login session IDs, tokens used for X (formerly Twitter) integration, Google single sign-on email addresses, and other profile data.[7][10][11] The company stressed that it does not store payment card numbers within Gyazo, and there is currently no indication that financial information was compromised.[1][10][13] With roughly 23 million registered users on the service, the number of leaked user records is effectively equivalent to almost the entire user base.[6][11]
The breach goes beyond account data, extending to massive volumes of metadata tied to uploaded images, including identifiers that underpin Gyazo’s share links.[3][5][15] Helpfeel and independent coverage have warned that possession of these identifiers could allow an attacker to reconstruct URLs and access images, raising the possibility that some non-public or sensitive captures may have been viewed by unauthorized parties.[5][7][8] Most of the affected metadata is reported to be associated with content uploaded prior to 2019, but the investigation into what was accessed and how widely it may be abused remains ongoing.[2][3][15]
Helpfeel has not referenced any specific CVE designation or public vulnerability catalog entry for the flaw in Gyazo’s upload infrastructure, and there are no advisories listed in major vulnerability databases as of publication, suggesting the bug may be internally discovered and patched without a formal identifier at this stage.[1][10][15] The company says it has engaged external specialists to support its incident response and has notified Japan’s Personal Information Protection Commission, signaling that regulatory scrutiny is likely to follow.[13][14] No threat actor group has been publicly attributed, and there are currently no confirmed reports of the stolen data being weaponized in large-scale credential-stuffing or extortion campaigns.[2][4][8]
For users and organizations that rely on Gyazo to capture and share screenshots, the breach significantly raises the risk of account compromise and unauthorized viewing of historical captures, particularly where weak passwords, reused credentials, or persistent login sessions are in play.[2][4][5] Security teams should assume that associated email addresses, password hashes, session IDs, and third-party integration tokens may be in hostile hands and move quickly to force password resets, revoke and reissue tokens, invalidate active sessions, and review access policies for sensitive workflows that depend on Gyazo links.[4][5][12] Until Helpfeel provides further technical details, defenders will need to treat the incident as a reminder that seemingly simple utilities such as screenshot tools can represent high-value data stores, demanding the same level of hardening, monitoring, and breach planning as more traditional business applications.[3][4][8]
References
- Notice and Apology Regarding a Data Breach Resulting …
- Gyazo Breach Exposes 23.62 Million User Records and …
- Gyazo Breach Exposes 23 Million User Records and Image IDs
- 23 Million User Records Compromised in Gyazo Data Breach
- Gyazo Breach Exposes Link IDs Behind Private Captures
- Investigation Report on the Gyazo Unauthorized Access …
- Gyazoに不正アクセス ユーザー情報約2362万件、画像メタデータ約4.9億件が流出
- Gyazo Breach: 23.6M User Records After Upload Hack
- 「Gyazo」への不正アクセスによる情報漏えいに関するお知らせとお詫び
- ユーザー情報約2362万件・画像メタデータ約4.9億件が漏えい
- 画像共有サービス「Gyazo」に不正アクセス、2300万件超の情報 …
- Japan’s Helpfeel says Gyazo data breach exposed 24m …
- 「Gyazo」に不正アクセス。メールアドレスやX連携用トークンなどユーザー情報など約2,362万件が漏洩
- Web Security — Latest News, Reports & Analysis | The Hacker News