Helpfeel Inc., the Kyoto-based company behind the popular screenshot and image-sharing tool Gyazo, disclosed a data breach on September 16, 2026 that exposed approximately 23.62 million user records and roughly 490 million image metadata records, according to a notice the company published and The Hacker News reported.
What Happened
Helpfeel said it detected suspicious activity on Gyazo's image upload server on the evening of September 11, Japan time. Investigators determined that an attacker exploited a vulnerability in the upload server that allowed arbitrary commands to be run on Helpfeel's systems, giving the intruder access to Gyazo's database. By the early hours of September 12, Helpfeel says it had identified and blocked the access routes used in the intrusion, cut the attacker's connection, and patched the underlying vulnerability the same day.
The company said it confirmed the scope of the data exposure by September 14 and reported the incident to Japan's Personal Information Protection Commission on September 15, ahead of the public notice published September 16. Helpfeel has engaged an outside forensics firm to continue the investigation and says it is working to identify which specific users were affected so it can notify them individually.
Notably, coverage of the incident has pointed out that Gyazo's public status messages during the outage described the disruption as "maintenance" rather than disclosing that a breach was underway, a detail that drew some criticism once the fuller timeline emerged.
What Data Was Exposed
| Data Type | Record Count | Sensitivity |
|---|---|---|
| User records (emails, password hashes, device/session IDs, SSO tokens, profile and billing metadata) | approximately 23.62 million | High |
| Image metadata (image IDs, upload IPs, user-agents, EXIF location data, OCR text, hashed passphrases for private images) | approximately 490 million, mostly images from January 2019 or earlier | High |
Helpfeel's notice said the user records include email addresses and password hashes, along with device IDs, login session IDs, X (formerly Twitter) integration tokens, Google single sign-on email addresses, profile information, language preferences, registration and login timestamps, and subscription and billing status. The company did not specify which hashing algorithm was used to protect the passwords.
The image metadata haul is largely made up of the 32-character IDs that form Gyazo's shareable image links, along with upload IP addresses, browser user-agent strings, EXIF location data embedded in images, OCR-extracted text, image titles, and hashed passphrases used to protect some private images. Helpfeel said no payment card information was affected.
Why It Matters
Gyazo is a widely used screenshot and image-hosting tool embedded in workflows across IT support, software development, and general office collaboration, so the exposed email addresses and account data touch a broad, often security-conscious user base. Whether the leaked password hashes translate into real account-takeover risk depends heavily on the hashing algorithm and work factor Helpfeel used, details the company's notice did not disclose. Weakly hashed or unsalted passwords could be cracked in bulk, while a strong, modern algorithm would blunt that risk considerably.
The image metadata exposure carries its own risk profile. Because a Gyazo capture is normally protected only by the secrecy of the link containing its unique image ID, the leak of roughly 490 million of those IDs means attackers could potentially view images that were never meant to be public, even without a password. Helpfeel acknowledged this risk directly, saying it temporarily disabled viewing of some images as a precaution. At this scale, the metadata alone, including upload times, IP addresses, and embedded location data, could also let an attacker reconstruct usage patterns tied to specific accounts.
What Users Should Do
- Change your Gyazo password immediately, and change it on any other account where you reused the same or a similar password.
- Enable two-factor authentication on your Gyazo account if it is available, and on any linked accounts (Google, X/Twitter) tied to Gyazo's single sign-on integration.
- Watch for phishing emails or messages that reference the Gyazo breach, impersonate Helpfeel support, or ask you to "verify" your account, since attackers frequently exploit breach disclosures for follow-on scams.
- Treat any Gyazo links you have shared, especially for private or sensitive captures, as potentially exposed, and consider deleting or re-uploading sensitive images under new links where possible.
Company Response
Helpfeel has asked all Gyazo users to change their passwords, both on Gyazo and on any other service using the same credentials, and to watch for suspicious communications referencing the incident. The company says it disabled viewing of some images to limit the risk from exposed link IDs, engaged an external forensics firm, reported the breach to Japan's Personal Information Protection Commission, and committed to reviewing its authentication and authorization design and strengthening monitoring going forward.
Helpfeel said its related products, Helpfeel and Cosense, use different system architectures than Gyazo, and that its investigation so far has not found unauthorized disclosure of data from those systems, though some images displayed inside Helpfeel and Cosense via Gyazo may be temporarily unavailable because of the suspended image delivery. The company said it plans to email affected users directly where it has a registered address, and to post notices through the Gyazo web interface for anonymous accounts without one. Details on the exact password hashing algorithm used, and a final count of individually affected people as opposed to records, since many records share the same user, were not available at the time of writing.