Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2948+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Gyazo Breach Exposes 23.6 Million User Records and 490M Image Metadata
Gyazo Breach Exposes 23.6 Million User Records and 490M Image Metadata
NEWS

Gyazo Breach Exposes 23.6 Million User Records and 490M Image Metadata

Helpfeel confirms attackers exploited an upload server flaw at image host Gyazo, exposing 23.6M user records and 490M image metadata entries.

Dylan H.

News Desk

September 20, 2026
3 min read

Upload Server Flaw Exploited

Helpfeel, the Kyoto-based company behind the popular image-sharing service Gyazo, has disclosed a major data breach after an attacker exploited a vulnerability in the platform's image upload server to execute unauthorized commands and access backend systems. Unauthorized access occurred on September 11, 2026, with suspicious activity detected later that same evening.

Gyazo is especially popular in gaming communities and claims roughly 23 million users worldwide who have submitted over 3.1 billion media items to the service.


Scale of Exposure

Data SetRecords Exposed
User records~23.62 million
Image metadata records~490 million (mostly pre-2019)
Additional image metadata (via targeted search)~2.4 million

The compromised user information includes names, email addresses, password hashes, user and device IDs, X (Twitter) integration tokens, profile information, usage statistics, and billing information. Helpfeel states that payment card numbers were not compromised.

The exposed image metadata includes the IDs that compose Gyazo image-sharing links — meaning those IDs could potentially be used to view images without authorization. The attacker also obtained a list identifying which images were marked private, and Helpfeel says it cannot currently rule out that some private images were viewed during the intrusion.


Response Timeline

Sep 11, 2026  — Attacker exploits upload server vulnerability, gains backend access
Sep 11, 2026  — Suspicious activity detected the same evening
Sep 12, 2026  — Access routes blocked, attacker connections terminated, flaw patched
Sep 15, 2026  — Incident reported to Japan's Personal Information Protection Commission
Sep 2026      — Service taken offline for maintenance; external forensics engaged

Helpfeel says the ~23.62 million affected records include a number of anonymous accounts with no registered email address, and the company is still working to determine the actual number of individuals whose personal information was disclosed without authorization.


What Gyazo Users Should Do

  1. Change your Gyazo password immediately
  2. Change the password anywhere else you reused it — password hashes were exposed and may eventually be cracked
  3. Revoke and re-link X (Twitter) integrations tied to your Gyazo account
  4. Watch for phishing referencing this breach, especially messages claiming to be from Helpfeel or Gyazo support
  5. Review billing information on file with Gyazo if you have a paid subscription

Why This Matters

Image-hosting platforms are often treated as low-risk infrastructure, but the exposure of authentication tokens, billing data, and — potentially — private image access defeats that assumption. The scale here (23.6 million user records plus nearly half a billion metadata entries) puts Gyazo among the larger disclosed breaches of 2026, and the uncertainty around private image access is likely to keep this story developing as Helpfeel's forensic investigation continues.


References

  • BleepingComputer — Gyazo server flaw exploited to steal 23.6 million user records
  • SecurityWeek — 23 Million User Records Compromised in Gyazo Data Breach
  • The Hacker News — Gyazo Breach Exposes 23.62 Million User Records
  • Helpfeel — Notice and Apology Regarding a Data Breach

Related Reading

  • Substack Data Breach 700K Users
  • Panera Bread ShinyHunters 5 Million Leak
  • ADT Says Customer Data Stolen in Cyber Intrusion
#Data Breach#Gyazo#Helpfeel#Image Hosting#Credential Exposure

Related Articles

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A Gyazo image-upload server flaw exposed 23.62 million user records and 490 million image metadata records, Helpfeel says.

5 min read

Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

A newly disclosed critical vulnerability in cPanel and WHM tracked as CVE-2026-41940 is being mass-exploited by ransomware actors to breach web hosting...

5 min read

Wesco Confirms Security Incident After ExfilSquad Claims 2.6M Record Theft

Fortune 500 distributor Wesco confirmed a breach of its cloud CRM after ExfilSquad published 2.6M allegedly stolen records when ransom talks failed.

3 min read
Back to all News