Upload Server Flaw Exploited
Helpfeel, the Kyoto-based company behind the popular image-sharing service Gyazo, has disclosed a major data breach after an attacker exploited a vulnerability in the platform's image upload server to execute unauthorized commands and access backend systems. Unauthorized access occurred on September 11, 2026, with suspicious activity detected later that same evening.
Gyazo is especially popular in gaming communities and claims roughly 23 million users worldwide who have submitted over 3.1 billion media items to the service.
Scale of Exposure
| Data Set | Records Exposed |
|---|---|
| User records | ~23.62 million |
| Image metadata records | ~490 million (mostly pre-2019) |
| Additional image metadata (via targeted search) | ~2.4 million |
The compromised user information includes names, email addresses, password hashes, user and device IDs, X (Twitter) integration tokens, profile information, usage statistics, and billing information. Helpfeel states that payment card numbers were not compromised.
The exposed image metadata includes the IDs that compose Gyazo image-sharing links — meaning those IDs could potentially be used to view images without authorization. The attacker also obtained a list identifying which images were marked private, and Helpfeel says it cannot currently rule out that some private images were viewed during the intrusion.
Response Timeline
Sep 11, 2026 — Attacker exploits upload server vulnerability, gains backend access
Sep 11, 2026 — Suspicious activity detected the same evening
Sep 12, 2026 — Access routes blocked, attacker connections terminated, flaw patched
Sep 15, 2026 — Incident reported to Japan's Personal Information Protection Commission
Sep 2026 — Service taken offline for maintenance; external forensics engagedHelpfeel says the ~23.62 million affected records include a number of anonymous accounts with no registered email address, and the company is still working to determine the actual number of individuals whose personal information was disclosed without authorization.
What Gyazo Users Should Do
- Change your Gyazo password immediately
- Change the password anywhere else you reused it — password hashes were exposed and may eventually be cracked
- Revoke and re-link X (Twitter) integrations tied to your Gyazo account
- Watch for phishing referencing this breach, especially messages claiming to be from Helpfeel or Gyazo support
- Review billing information on file with Gyazo if you have a paid subscription
Why This Matters
Image-hosting platforms are often treated as low-risk infrastructure, but the exposure of authentication tokens, billing data, and — potentially — private image access defeats that assumption. The scale here (23.6 million user records plus nearly half a billion metadata entries) puts Gyazo among the larger disclosed breaches of 2026, and the uncertainty around private image access is likely to keep this story developing as Helpfeel's forensic investigation continues.
References
- BleepingComputer — Gyazo server flaw exploited to steal 23.6 million user records
- SecurityWeek — 23 Million User Records Compromised in Gyazo Data Breach
- The Hacker News — Gyazo Breach Exposes 23.62 Million User Records
- Helpfeel — Notice and Apology Regarding a Data Breach